CVE-2025-49837: Rvc-Boss Gpt-Sovits-Webui

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of AudioPre class is created with the model_path attribute containing the aforementioned user input (here called locally model_name). Note that in this step the .pth extension is added to the path. In the AudioPre class, the user input, here called model_path, is used to load the model on that path with torch.load, which can lead to unsafe deserialization. At time of publication, no known patched versions are available.

Affected products

  • Rvc-Boss Gpt-Sovits-Webui: up to and including 20250228v3

Published 2025-07-15. Last modified 2026-06-17.