PT-2026-41566 · Fishaudio · Bert-Vits2
Eric-B
·
Published
2026-05-17
·
Updated
2026-05-18
·
CVE-2026-8755
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
fishaudio Bert-VITS2 versions prior to 8f7fbd8c4770965225d258db548da27dc8dd934c
Description
A path traversal flaw exists in the Model Handler component, specifically within the
get all models() function of the hiyoriUI.py file. This issue allows a remote attacker to manipulate file paths to access unauthorized directories.Recommendations
Update fishaudio Bert-VITS2 to a version later than 8f7fbd8c4770965225d258db548da27dc8dd934c.
As a temporary workaround, restrict access to the
get all models() function in the hiyoriUI.py file to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bert-Vits2