CVE-2025-62187

low

Description

In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).

References

https://github.com/ankitects/anki/releases/tag/25.02.6

https://github.com/ankitects/anki/pull/4041/commits/51476e05b281737a0c2924342bccdb6e5be52ea9

https://github.com/ankitects/anki/pull/4041

Details

Source: Mitre, NVD

Published: 2025-10-07

Updated: 2025-10-10

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00011