CVE-2024-29073
Python vulnerability analysis and mitigation

Overview

An arbitrary file read vulnerability (CVE-2024-29073) was discovered in Ankitects Anki version 24.04. The vulnerability exists in the handling of LaTeX content, where the verbatim package, which comes installed by default in many LaTeX distributions, was overlooked during the sanitization process of unsafe commands. The vulnerability was discovered by Autumn Bee Skerritt of Cisco Duo Security and Jacob B, and was publicly disclosed on July 22, 2024 (Talos Report).

Technical details

The vulnerability stems from incomplete sanitization of LaTeX commands in Anki's flashcard system. While Anki implements a blocklist to prevent the use of commands that read file descriptors, the verbatim package command was overlooked. An attacker can exploit this by crafting a special card header section that loads the verbatim package and subsequently abuse its functionality through the verbatiminput tag. The vulnerability has been assigned a CVSS v3.1 score of 5.3 (Medium) with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N, and is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) (Talos Report).

Impact

The vulnerability allows an attacker to perform arbitrary file reads on the target system. Additionally, it can be used to gather system information and list directories/files. The attacker can retrieve the results by exploiting the fact that the content is associated with the HTML document tag 'img.latex' and using JavaScript code in the card template to exfiltrate the data to an attacker-controlled server (Talos Report).

Exploitability

The vulnerability can be triggered by sharing a specially crafted flashcard with a target user. Anki's design allows users to publicly share their decks, and there are no warnings or checks in place to prevent using cards from other users. The exploitation requires the target to have a LaTeX handler installed (such as MiKTeX for Windows users) (Talos Report).

Mitigation and workarounds

The vulnerability was patched with a vendor release on June 24, 2024. Users should update to a version newer than Anki 24.04 to protect against this vulnerability (Talos Report).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48169HIGH8.8
  • Python logoPython
  • praisonai-platform
NoYesAug 07, 2026
CVE-2026-48813HIGH8.7
  • Python logoPython
  • flawfinder
NoYesAug 11, 2026
CVE-2026-48804HIGH7.5
  • Python logoPython
  • python311-python-socketio
NoYesAug 11, 2026
CVE-2026-48809HIGH7.5
  • Python logoPython
  • python313-python-engineio
NoYesAug 11, 2026
CVE-2026-48802HIGH7.5
  • Python logoPython
  • python311-python-engineio
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management