CVE-2024-32944: Ameya/ayame Utau

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip file) to UTAU, an arbitrary file may be placed.

Affected products

Published 2024-05-28. Last modified 2026-06-17.