CVE-2025-43703 is a medium-severity vulnerability affecting Ankitects Anki through version 25.02, allowing a crafted shared deck to grant unauthorized access to the internal API. This issue, an incomplete fix for a previous CVE, has a CVSS score of 5.4, indicating low impact on confidentiality and integrity with no impact on availability. Exploitation requires user interaction via a network-based attack, but no public exploit code, Metasploit modules, or Nuclei templates are currently available. There is also no evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.02CPE matchmatch criteria | cpe:2.3:a:ankitects:anki:*:*:*:*:*:*:*:* | ||
>= 0, <= 25.02CPE match | cpe:2.3:a:ankitects:anki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.