漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
Vulnerability Description
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated POST request to the /wav2wav route. Attackers can pass arbitrary server-side paths verbatim to librosa.load, torchaudio.load, and soundfile.write sinks, causing the server to decode and return file contents via the HTTP response body while also writing attacker-specified .wav files to arbitrary locations on the filesystem.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
MoeVoiceConversion SoftVC VITS Singing Voice Conversion 路径遍历漏洞
Vulnerability Description
MoeVoiceConversion SoftVC VITS Singing Voice Conversion是MoeVoiceConversion团队开源的一款基于神经网络的歌声转换工具。 MoeVoiceConversion SoftVC VITS Singing Voice Conversion 730930d及之前版本存在路径遍历漏洞,该漏洞源于全曲推理服务器中存在路径遍历,允许未经身份验证的远程攻击者通过向/wav2wav路由发送未经身份验证的POST请求的audio_path字段提供攻击者控制
CVSS Information
N/A
Vulnerability Type
N/A