External Control of File Name or Path in Anki - #VU150785

 

External Control of File Name or Path in Anki - #VU150785

Published: September 17, 2026


Vulnerability identifier: #VU150785
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to external control of file name or path in the openFolder function in qt/aqt/utils.py when opening an image from a malicious flashcard deck in the editor. A remote attacker can embed an image tag with a path containing a dangerous extension in its src attribute and induce the victim to select the \"Open image\" action to execute arbitrary code.

User interaction is required to select the \"Open image\" action.


Affected software

Anki

Remediation

Install security update from vendor's website.

Anki - update to 26.09

External References

Related Security Bulletins