CVE-2025-62187: CWE-23 Relative Path Traversal in Ankitects Anki
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
CVE-2025-62187: CWE-23 Relative Path Traversal in Ankitects Anki
Description
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-10-07T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68e582fea677756fc9a25d5e
Added to database: 10/7/2025, 9:15:42 PM
Last updated: 10/7/2025, 9:15:58 PM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2025-34252: CWE-506 Embedded Malicious Code in NetSarang Computer, Inc. Xmanager Enterprise
CriticalCVE-2025-11409: SQL Injection in Campcodes Advanced Online Voting Management System
MediumCVE-2025-62185: CWE-427 Uncontrolled Search Path Element in Ankitects Anki
MediumCVE-2025-62186: CWE-829 Inclusion of Functionality from Untrusted Control Sphere in Ankitects Anki
MediumCVE-2025-11408: Buffer Overflow in D-Link DI-7001 MINI
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.