PT-2025-11977 · Applio · Applio
Published
2025-03-19
·
Updated
2025-08-01
·
CVE-2025-27775
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Applio versions 3.2.7 and prior
Description
Applio is a voice conversion tool vulnerable to server-side request forgery (SSRF) and file write within the
model download.py file (line 143 in version 3.2.7). The SSRF allows sending requests on behalf of the Applio server, potentially enabling probing for other vulnerabilities on the server or internal network systems accessible to the Applio server. The file write capability allows writing files on the server, which, in conjunction with other vulnerabilities like unsafe deserialization, could lead to remote code execution on the Applio server.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Applio