{"id":"CVE-2024-26020","aliases":["GHSA-9gq7-p5w9-w899","PYSEC-2026-1116"],"url":"https://o3.security/vulnerability/CVE-2024-26020","summary":"Ankitects Anki arbitrary script execution vulnerability","details":"An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.","published":"2024-07-22T14:20:26.617Z","modified":"2026-08-12T03:51:31.418239133Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"anki","fixedVersion":"24.06"}],"fix":{"url":"https://github.com/ankitects/anki/commit/8d2e8b1e4fa3757581f224b1a57057d0455352ce","label":"ankitects/anki@8d2e8b1"},"references":[{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993"},{"type":"WEB","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1993"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26020.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26020"},{"type":"WEB","url":"https://github.com/ankitects/anki/commit/8d2e8b1e4fa3757581f224b1a57057d0455352ce"},{"type":"PACKAGE","url":"https://github.com/ankitects/anki"},{"type":"WEB","url":"https://skerritt.blog/anki-0day"},{"type":"WEB","url":"https://skii.dev/anki-0day"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.418239133Z"}}