GPT-SoVITS-WebUI是RVC-Boss个人开发者的一个TTS训练模型。 GPT-SoVITS-WebUI 20250228v3及之前版本存在代码问题漏洞,该漏洞源于bsroformer.py存在不安全反序列化,可能导致执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RVC-Boss | GPT-SoVITS | <= 20250228v3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-49834 | GHSL-2025-046: GPT-SoVITS Command Injection vulnerability | |
| CVE-2025-49833 | GHSL-2025-045: GPT-SoVITS Command Injection vulnerability | |
| CVE-2025-49838 | GHSL-2025-050: GPT-SoVITS Deserialization of Untrusted Data vulnerability | |
| CVE-2025-49841 | GHSL-2025-053: GPT-SoVITS Deserialization of Untrusted Data vulnerability | |
| CVE-2025-49840 | GHSL-2025-052: GPT-SoVITS Deserialization of Untrusted Data vulnerability | |
| CVE-2025-49836 | GHSL-2025-048: GPT-SoVITS Command Injection vulnerability | |
| CVE-2025-49835 | GHSL-2025-047: GPT-SoVITS Command Injection vulnerability | |
| CVE-2025-49837 | GHSL-2025-049: GPT-SoVITS Deserialization of Untrusted Data vulnerability |
No comments yet