CVE-2025-43849

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. Theckpt_aandcpkt_bvariables take user input(e.g. a path to a model) andpassit to themergefunction inprocess_ckpt.py, which uses them toload the models on those paths withtorch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GitHub_MCNA
---
---
CISA-ADPADP
---
---