External Control of File Name or Path in Anki - #VU150785
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to external control of file name or path in the openFolder function in qt/aqt/utils.py when opening an image from a malicious flashcard deck in the editor. A remote attacker can embed an image tag with a path containing a dangerous extension in its src attribute and induce the victim to select the \"Open image\" action to execute arbitrary code.
User interaction is required to select the \"Open image\" action.