Relative Path Traversal in Anki - CVE-2025-62187
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to write files to arbitrary location on the system.
The vulnerability exists due to improper input validation when processing sound file references in qt/aqt/sound.py. A remote attacker can trick the victim into opening a specially crafted sound file and write files to arbitrary location on the system, leading to remote code execution.