Unsafe Deserialization Vulnerability in GPT-SoVITS-WebUI by RVC-Boss
CVE-2025-49841

8.9HIGH

Key Information:

Vendor

Rvc-boss

Vendor
CVE Published:
15 July 2025

What is CVE-2025-49841?

The GPT-SoVITS-WebUI, a voice conversion and text-to-speech application, is vulnerable to unsafe deserialization in versions 20250228v3 and earlier. The vulnerability arises from the SoVITS_dropdown variable accepting user input, which is subsequently passed to the load_sovits_new function in process_ckpt.py. This leads to an insecure loading process through torch.load, exposing the system to potential malicious input. As of the latest information available, there are no patched versions released to address this issue, which requires immediate attention from users and developers.

Affected Version(s)

GPT-SoVITS <= 20250228v3

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49841 : Unsafe Deserialization Vulnerability in GPT-SoVITS-WebUI by RVC-Boss