VYPR
Critical severity9.8NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-49840

CVE-2025-49840

Description

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in inference_webui.py. The GPT_dropdown variable takes user input and passes it to the change_gpt_weights function. In change_gpt_weights, the user input, here gpt_path is used to load a model with torch.load, leading to unsafe deserialization. At time of publication, no known patched versions are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rvc Boss/Gpt Sovitsllm-fuzzy2 versions
    <=20250228v3+ 1 more
    • (no CPE)range: <=20250228v3
    • (no CPE)range: <= 20250228v3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.