VYPR
Critical severity9.8NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-49834

CVE-2025-49834

Description

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_denoise function. denoise_inp_dir and denoise_opt_dir take user input, which is passed to the open_denoise function, which concatenates the user input into a command and runs it on the server, leading to arbitrary command execution. At time of publication, no known patched versions are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rvc Boss/Gpt Sovitsllm-fuzzy2 versions
    <=20250228v3+ 1 more
    • (no CPE)range: <=20250228v3
    • (no CPE)range: <= 20250228v3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.