-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The core vulnerability stems from improper argument handling in subprocess.Popen calls that concatenated untrusted filenames with MPV/mplayer arguments without using the POSIX '--' separator. The commit 8d2e8b1 explicitly fixes this by adding '--' before filenames. The _play functions in sound.py directly used user-controlled filenames as command arguments, allowing MPV to interpret them as command-line flags. High confidence for SimpleMpvPlayer due to explicit Windows RCE PoC in advisories, medium for mplayer as impact depends on specific capabilities.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| anki | pip | < 24.06 | 24.06 |
KEV Misses 88% of Exploited CVEs- Get the report