CVE-2024-32944: Ameya/ayame Utau
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip file) to UTAU, an arbitrary file may be placed.
Affected products
- Ameya/ayame Utau: before v0.4.19 (fixed in v0.4.19)
Published 2024-05-28. Last modified 2026-06-17.