Anki · Anki · CVE-2025-62185
**Name of the Vulnerable Software and Affected Versions**
Anki versions prior to 25.02.5
**Description**
A specially designed shared deck can place a YouTube downloader executable in the media folder. This executable is then run when a YouTube link is present within the deck. The executable may be named `youtube-dl.exe`, `yt-dlp.exe`, or `yt-dlp x86.exe`.
**Recommendations**
Update to version 25.02.5 or later.