Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load the model on that path with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
History

Mon, 05 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 May 2025 18:30:00 +0000

Type Values Removed Values Added
Description Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load the model on that path with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
Title GHSL-2025-020_Retrieval-based-Voice-Conversion-WebUI
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-05T18:20:57.088Z

Updated: 2025-05-05T18:53:43.138Z

Reserved: 2025-04-17T20:07:08.555Z

Link: CVE-2025-43850

cve-icon Vulnrichment

Updated: 2025-05-05T18:53:38.384Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-05T19:15:56.090

Modified: 2025-05-05T20:54:19.760

Link: CVE-2025-43850

cve-icon Redhat

No data.