VYPR
Critical severity9.8NVD Advisory· Published Jul 15, 2025· Updated Jun 17, 2026

CVE-2025-49841

CVE-2025-49841

Description

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in process_ckpt.py. The SoVITS_dropdown variable takes user input and passes it to the load_sovits_new function in process_ckpt.py. In load_sovits_new, the user input, here sovits_path is used to load a model with torch.load, leading to unsafe deserialization. At time of publication, no known patched versions are available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rvc Boss/Gpt Sovitsllm-fuzzy2 versions
    <=20250228v3+ 1 more
    • (no CPE)range: <=20250228v3
    • (no CPE)range: <= 20250228v3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.