CVE-2025-43842

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variablesexp_dir1,np7,trainset_dir4andsr2take user input andpassit to thepreprocess_datasetfunction, whichconcatenates them into a commandthat isrunon the server. This can lead to arbitrary command execution. As of time of publication, no known patches exist.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GitHub_MCNA
---
---
CISA-ADPADP
---
---