CVE-2025-43845
05.05.2025, 18:15
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. Theckpt_path2variabletakes user input(e.g. a path to a model) andpassesit tochange_info_function, which opens and reads the file on the given path (except it changes the final on the path totrain.log), andpasses the contents of the file toeval, which can lead to remote code execution. As of time of publication, no known patches exist.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References