PT-2025-11977 · Applio · Applio

Published

2025-03-19

·

Updated

2025-08-01

·

CVE-2025-27775

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Applio versions 3.2.7 and prior
Description Applio is a voice conversion tool vulnerable to server-side request forgery (SSRF) and file write within the model download.py file (line 143 in version 3.2.7). The SSRF allows sending requests on behalf of the Applio server, potentially enabling probing for other vulnerabilities on the server or internal network systems accessible to the Applio server. The file write capability allows writing files on the server, which, in conjunction with other vulnerabilities like unsafe deserialization, could lead to remote code execution on the Applio server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-27775

Affected Products

Applio