- Description
- Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge function in process_ckpt.py, which uses them to load the models on those paths with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security-advisories@github.com
- CWE-502
- Hype score
- Not currently trending
🚨 CVE-2025-43849 🔴 HIGH (8.9) 🏢 RVC-Project - Retrieval-based-Voice-Conversion-WebUI 🏗️ <= 2.2.231006 🔗 https://t.co/KaJuP86HaX 🔗 https://t.co/0KxByl541B 🔗 https://t.co/aX5pmhKKeL 🔗 https://t.co/MoxUDeGqV5 🔗 https://t.co/KuZvI36pzM #CyberCron #Vuln
@cybercronai
7 May 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-43849 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a… https://t.co/fYtw5SiB1P
@CVEnew
5 May 2025
349 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-43849: HIGH] Voice Conversion WebUI based on VITS is at risk due to unsafe deserialization - Versions 2.2.231006 and earlier allow for remote code execution. No patches available currently.#cve,CVE-2025-43849,#cybersecurity https://t.co/15WkMutdgw https://t.co/vrS1jaKO0
@CveFindCom
5 May 2025
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes