CVE-2025-43843

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variablesexp_dir1,np7andf0method8take user input andpassit into theextract_f0_featurefunction, whichconcatenates them into a commandthat is run on the server. This can lead to arbitrary command execution. As of time of publication, no known patches exist.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GitHub_MCNA
---
---
CISA-ADPADP
---
---