8.8

CVSS4.0

CVE-2025-27775 - Applio allows SSRF and file write in model_download.py

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 143 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities o…

πŸ“… Published: March 19, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:50 a.m.

8.8

CVSS4.0

CVE-2025-27776 - Applio allows SSRF and file write in model_download.py

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 240 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities o…

πŸ“… Published: March 19, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:47 a.m.

7.7

CVSS4.0

CVE-2025-27777 - Applio allows SSRF and file write in model_download.py

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities on the server it…

πŸ“… Published: March 19, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:42 a.m.

8.9

CVSS4.0

CVE-2025-27778 - Applio allows unsafe deserialization in infer.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of the Applio repository but not attached to a numbered release.

πŸ“… Published: March 19, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:41 a.m.

8.9

CVSS4.0

CVE-2025-27779 - Applio allows unsafe deserialization in model_blender.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a path to a model) and pass that value to the `run_model_blen…

πŸ“… Published: March 19, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:39 a.m.

7.7

CVSS4.0

CVE-2025-27782 - Applio allows arbitrary file write in inference.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote code execution. As of t…

πŸ“… Published: March 19, 2025, 8:41 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:31 p.m.

7.7

CVSS4.0

CVE-2025-27783 - Applio allows arbitrary file write in train.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote code execution. As of time …

πŸ“… Published: March 19, 2025, 8:41 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:26 p.m.

7.7

CVSS4.0

CVE-2025-27784 - Applio allows arbitrary file read in train.py export_pth function

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files …

πŸ“… Published: March 19, 2025, 8:41 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:24 p.m.

7.8

CVSS4.0

CVE-2025-27787 - Applio allows a DoS in restart.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py takes user input, and passes it to the `stop_train` function in restart.py, which uses it construct a path to a folder with `config.json`. That `confi…

πŸ“… Published: March 19, 2025, 8:41 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:03 p.m.

7.8

CVSS4.0

CVE-2025-27786 - Applio allows arbitrary file removal in core.py

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input and passes it to `run_tts_script` function in core.py, which checks if the path in `output_tts_path` exists, and if yes, rem…

πŸ“… Published: March 19, 2025, 8:37 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 4:12 p.m.
Total resulsts: 349182
Page 6301 of 34,919
Β« previous page Β» next page
Filters