Stakira · Openutau · CVE-2022-4880
**Name of the Vulnerable Software and Affected Versions**
stakira OpenUtau versions prior to 0.0.991
**Description**
A critical issue was found in the ZIP Archive Handler component, specifically affecting the `VoicebankInstaller` function of the file OpenUtau.Core/Classic/VoicebankInstaller.cs. This issue leads to path traversal.
**Recommendations**
For versions prior to 0.0.991, upgrade to version 0.0.991 to address this issue. As a temporary workaround, consider disabling the `VoicebankInstaller` function until the upgrade is applied.