VYPR
Critical severity9.8NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-49836

CVE-2025-49836

Description

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. path_list takes user input, which is passed to the change_label function, which concatenates the user input into a command and runs it on the server, leading to arbitrary command execution. At time of publication, no known patched versions are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rvc Boss/Gpt Sovitsllm-fuzzy2 versions
    <=20250228v3+ 1 more
    • (no CPE)range: <=20250228v3
    • (no CPE)range: <= 20250228v3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.