Description
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of AudioPre class is created with the model_path attribute containing the aforementioned user input (here called locally model_name). Note that in this step the .pth extension is added to the path. In the AudioPre class, the user input, here called model_path, is used to load the model on that path with torch.load, which can lead to unsafe deserialization. At time of publication, no known patched versions are available.
INFO
Published Date :
2025-07-15T20:34:47.287Z
Last Modified :
2025-07-16T13:44:35.627Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-49837 vulnerability.
| Vendors | Products |
|---|---|
| Rvc-boss |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-49837.