CVE-2025-43849
05.05.2025, 19:15
Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. Theckpt_aandcpkt_bvariables take user input(e.g. a path to a model) andpassit to themergefunction inprocess_ckpt.py, which uses them toload the models on those paths withtorch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.Enginsight
Vendor | Product | Version |
---|---|---|
rvc-project | retrieval-based-voice-conversion-webui | 𝑥 ≤ 2.2.231006 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References