VYPR
High severity7.5NVD Advisory· Published Mar 19, 2025· Updated Jun 17, 2026

CVE-2025-27785

CVE-2025-27785

Description

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's export_index function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • GitHub/Appliollm-create
    Range: <=3.2.8-bugfix
  • Applio/Appliollm-fuzzy
    Range: <=3.2.8-bugfix
  • IAHispano/Appliov5
    Range: <= 3.2.8-bugfix

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.