VYPR
Critical severity9.8NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-49839

CVE-2025-49839

Description

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Roformer_Loader class is created with the model_path attribute containing the aformentioned user input (here called locally model_name). Note that in this step the .ckpt extension is added to the path. In the Roformer_Loader class, the user input, here called model_path, is used to load the model on that path with torch.load, which can lead to unsafe deserialization. At time of publication, no known patched versions are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rvc Boss/Gpt Sovitsllm-fuzzy2 versions
    <=20250228v3+ 1 more
    • (no CPE)range: <=20250228v3
    • (no CPE)range: <= 20250228v3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.