CVE-2024-26020

EUVD-2024-2309
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
talosCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96.5%
Affected Products (NVD)
VendorProductVersion
ankiwebanki
24.04
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ankitectsanki
24.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
anki
bullseye
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
anki
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
dne
questing
dne
resolute
dne
xenial
ignored