PT-2026-41566 · Fishaudio · Bert-Vits2

Eric-B

·

Published

2026-05-17

·

Updated

2026-05-18

·

CVE-2026-8755

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions fishaudio Bert-VITS2 versions prior to 8f7fbd8c4770965225d258db548da27dc8dd934c
Description A path traversal flaw exists in the Model Handler component, specifically within the get all models() function of the hiyoriUI.py file. This issue allows a remote attacker to manipulate file paths to access unauthorized directories.
Recommendations Update fishaudio Bert-VITS2 to a version later than 8f7fbd8c4770965225d258db548da27dc8dd934c. As a temporary workaround, restrict access to the get all models() function in the hiyoriUI.py file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8755

Affected Products

Bert-Vits2