Unsafe Deserialization Vulnerability in GPT-SoVITS-WebUI by RVC-Boss
CVE-2025-49841
8.9HIGH
What is CVE-2025-49841?
The GPT-SoVITS-WebUI, a voice conversion and text-to-speech application, is vulnerable to unsafe deserialization in versions 20250228v3 and earlier. The vulnerability arises from the SoVITS_dropdown variable accepting user input, which is subsequently passed to the load_sovits_new function in process_ckpt.py. This leads to an insecure loading process through torch.load, exposing the system to potential malicious input. As of the latest information available, there are no patched versions released to address this issue, which requires immediate attention from users and developers.
Affected Version(s)
GPT-SoVITS <= 20250228v3