CVE-2024-26020
Python vulnerability analysis and mitigation

Overview

An arbitrary script execution vulnerability (CVE-2024-26020) was discovered in the MPV functionality of Ankitects Anki 24.04. The vulnerability was disclosed on May 27, 2024, and patched on June 24, 2024. Anki is an open-source program that helps with memorization of information through flashcards, supporting various content types including images, audio, videos, and scientific notation (Talos Report).

Technical details

The vulnerability exists in the way Anki handles media files through MPV player on Windows. When playing sound files in flashcards, Anki passes arguments directly to MPV without proper sanitization. The vulnerability has a CVSS v3.1 score of 9.6 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) (Talos Report).

Impact

A successful exploitation of this vulnerability could lead to arbitrary code execution on the target system. An attacker can achieve full command injection capabilities on the user's system by crafting malicious flashcards (Talos Report).

Exploitability

The vulnerability can be triggered by sending a specially crafted flashcard to a target user. The exploit involves replacing standard media file references with malicious configuration files that can load and execute Lua scripts through MPV's configuration system. The attack requires user interaction to import the malicious flashcard deck (Talos Report).

Mitigation and workarounds

The vulnerability was patched in a vendor release on June 24, 2024. Users should update their Anki installations to versions newer than 24.04 to protect against this vulnerability (Talos Report).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84366HIGH7.4
  • Python logoPython
  • scrapy
NoYesSep 01, 2026
CVE-2026-53720MEDIUM5.1
  • Python logoPython
  • pymonocypher
NoYesSep 03, 2026
CVE-2026-84311MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
CVE-2026-84310MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
GHSA-wwv5-g3v4-889xLOW2.3
  • Python logoPython
  • tornado
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management