
Cloud Vulnerability DB
A community-led vulnerabilities database
An arbitrary script execution vulnerability (CVE-2024-26020) was discovered in the MPV functionality of Ankitects Anki 24.04. The vulnerability was disclosed on May 27, 2024, and patched on June 24, 2024. Anki is an open-source program that helps with memorization of information through flashcards, supporting various content types including images, audio, videos, and scientific notation (Talos Report).
The vulnerability exists in the way Anki handles media files through MPV player on Windows. When playing sound files in flashcards, Anki passes arguments directly to MPV without proper sanitization. The vulnerability has a CVSS v3.1 score of 9.6 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) (Talos Report).
A successful exploitation of this vulnerability could lead to arbitrary code execution on the target system. An attacker can achieve full command injection capabilities on the user's system by crafting malicious flashcards (Talos Report).
The vulnerability can be triggered by sending a specially crafted flashcard to a target user. The exploit involves replacing standard media file references with malicious configuration files that can load and execute Lua scripts through MPV's configuration system. The attack requires user interaction to import the malicious flashcard deck (Talos Report).
The vulnerability was patched in a vendor release on June 24, 2024. Users should update their Anki installations to versions newer than 24.04 to protect against this vulnerability (Talos Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."