CVE-2025-43847
05.05.2025, 18:15
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. Theckpt_path2variabletakes user input(e.g. a path to a model) andpassesit to theextract_small_modelfunction inprocess_ckpt.py, which uses it toload the model on that path withtorch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References