PT-2025-11984 · Applio · Applio

Sylwia Budzynska

+1

·

Published

2025-03-19

·

Updated

2025-08-01

·

CVE-2025-27784

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Applio versions 3.2.8-bugfix and prior
Description The issue affects a voice conversion tool and may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. The problem lies in the export pth function in train.py.
Recommendations For versions 3.2.8-bugfix and prior, as a temporary workaround, consider disabling the export pth function in train.py until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-27784

Affected Products

Applio