CVE-2026-63766: Rvc-Boss Gpt-Sovits

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.

Affected products

  • Rvc-Boss Gpt-Sovits: up to and including 20250606v2pro

Published 2026-07-20. Last modified 2026-07-23.