High severity7.5NVD Advisory· Published Mar 19, 2025· Updated Jun 17, 2026
CVE-2025-27784
CVE-2025-27784
Description
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's export_pth function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- IAHispano/Appliov5Range: <= 3.2.8-bugfix
Patches
Vulnerability mechanics
References
3- securitylab.github.com/advisories/GHSL-2024-341_GHSL-2024-353_Applio/nvdExploitVendor Advisory
- github.com/IAHispano/Applio/blob/29b4a00e4be209f9aac51cd9ccffcc632dfb2973/tabs/train/train.pynvdProduct
- github.com/IAHispano/Applio/blob/29b4a00e4be209f9aac51cd9ccffcc632dfb2973/tabs/train/train.pynvdProduct
News mentions
0No linked articles in our index yet.