Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on that path with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
History

Mon, 05 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 May 2025 18:00:00 +0000

Type Values Removed Values Added
Description Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on that path with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
Title GHSL-2025-018_Retrieval-based-Voice-Conversion-WebUI
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-05T17:54:58.884Z

Updated: 2025-05-05T18:25:04.426Z

Reserved: 2025-04-17T20:07:08.554Z

Link: CVE-2025-43848

cve-icon Vulnrichment

Updated: 2025-05-05T18:24:52.385Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-05T18:15:42.683

Modified: 2025-05-05T20:54:19.760

Link: CVE-2025-43848

cve-icon Redhat

No data.