CVE-2025-43847
05.05.2025, 18:15
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. Theckpt_path2variabletakes user input(e.g. a path to a model) andpassesit to theextract_small_modelfunction inprocess_ckpt.py, which uses it toload the model on that path withtorch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.Enginsight
Vendor | Product | Version |
---|---|---|
rvc-project | retrieval-based-voice-conversion-webui | 𝑥 ≤ 2.2.231006 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References