CVE-2026-63766: Rvc-Boss Gpt-Sovits
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.
Affected products
- Rvc-Boss Gpt-Sovits: up to and including 20250606v2pro
Published 2026-07-20. Last modified 2026-07-23.