CVE-2025-62186 PUBLISHED

Assigner: mitre
Reserved: 07.10.2025 Published: 07.10.2025 Updated: 07.10.2025

Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 6.7

Product Status

Vendor Ankitects
Product Anki
Versions Default: unaffected
  • affected from 0 to 25.02.5 (excl.)

References

Problem Types

  • CWE-829 Inclusion of Functionality from Untrusted Control Sphere CWE