In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.
References
Configurations
History
No history.
Information
Published : 2025-10-07 21:15
Updated : 2025-10-10 16:21
NVD link : CVE-2025-62185
Mitre link : CVE-2025-62185
CVE.ORG link : CVE-2025-62185
JSON object : View
Products Affected
ankitects
- anki
CWE
CWE-427
Uncontrolled Search Path Element
