Back to Database
Status published
Medium
CVE-2025-62185
In Ankitects Anki before 25.02.5, a crafted shared deck can...
Vulnerability Description
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62185
Credits & Attribution
No credits recorded in the NVD database.
References
More from Ankitects
View All →CVE-2025-62187
In Ankitects Anki before 25.02.6, crafted sound file references could...
Low
2.9
CVE-2025-62186
Ankitects Anki before 25.02.5 allows a crafted shared deck on...
Medium
6.7
CVE-2025-43703
An issue was discovered in Ankitects Anki through 25.02. A...
Medium
6.1
CVE-2024-32484
An reflected XSS vulnerability exists in the handling of invalid...
High
7.4
CVE-2024-32152
A blocklist bypass vulnerability exists in the LaTeX functionality of...
Low
3.1
Affected Vendor
Ankitects
View all reports →Affected Software
Anki
Vulnerable Versions:
0
Timeline
Official Publish:
October 7th, 2025
Last Modified:
October 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N