← Back to browse · API

CVE-2024-26020

Severity
CRITICAL
CVSS
9.6
EPSS
0.15067
Risk score
43.67
CISA KEV
No
PoC
No
Published
2024-07-22
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-2309, GHSA-9GQ7-P5W9-W899, PYSEC-2026-1116
Products
Ankitects:Anki 24.04
Sources
euvd EUVD-2024-2309

Description

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

References