PT-2025-29682 · Unknown · Gpt-Sovits-Webui

Sylwia Budzynska

+1

·

Published

2025-07-15

·

Updated

2025-07-16

·

CVE-2025-49840

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPT-SoVITS-WebUI versions 20250228v3 and prior
Description GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. An unsafe deserialization issue exists in the inference webui.py file. The application takes user input via the gpt path variable and passes it to the torch.load function, resulting in unsafe deserialization. The GPT dropdown variable receives user input which is then passed to the change gpt weights function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-49840

Affected Products

Gpt-Sovits-Webui