Metrics
Affected Vendors & Products
Mon, 05 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 05 May 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 05 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a command that is run on the server. This can lead to arbitrary command execution. As of time of publication, no known patches exist. | |
Title | GHSL-2025-012_Retrieval-based-Voice-Conversion-WebUI | |
Weaknesses | CWE-77 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-05T17:08:48.481Z
Updated: 2025-05-05T17:29:51.617Z
Reserved: 2025-04-17T20:07:08.553Z
Link: CVE-2025-43842

Updated: 2025-05-05T17:29:44.685Z

Status : Awaiting Analysis
Published: 2025-05-05T17:18:48.967
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-43842

No data.