CVE-2025-43843
05.05.2025, 17:18
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variablesexp_dir1,np7andf0method8take user input andpassit into theextract_f0_featurefunction, whichconcatenates them into a commandthat is run on the server. This can lead to arbitrary command execution. As of time of publication, no known patches exist.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References