Arbitrary Command Execution Vulnerability in Bert-VITS2
CVE-2024-39686
9.8CRITICAL
What is CVE-2024-39686?
The Bert-VITS2 product from Fishaudio is vulnerable due to improper handling of user input supplied to the data_dir variable. This flaw allows an attacker to execute arbitrary commands through the bert_gen function, which utilizes the subprocess.run method with shell=True. Versions 2.3 and earlier are notably affected, creating significant security risks for users who utilize this backbone for multilingual applications.
Affected Version(s)
Bert-VITS2 <= 2.3
