VYPR

F5-TTS

by SWivid

CVEs (1)

  • CVE-2026-43624HigJun 1, 2026
    risk 0.46cvss 8.2epss

    F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-supplied project names directly to os.path.join() without validating the resulting…