Vulnerability Description
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ankitects | Anki | < 25.02.5 |
Related Weaknesses (CWE)
References
- https://github.com/ankitects/anki/commit/5080451829505842b16d4a50f398ad44560a3e4Patch
- https://github.com/ankitects/anki/commit/6213c9b6f99ebda181004f8915b92fe3618b939Broken Link
- https://github.com/ankitects/anki/compare/25.02.4...25.02.5Patch
FAQ
What is CVE-2025-62185?
CVE-2025-62185 is a vulnerability with a CVSS score of 6.7 (MEDIUM). In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be...
How severe is CVE-2025-62185?
CVE-2025-62185 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62185?
Check the references section above for vendor advisories and patch information. Affected products include: Ankitects Anki.