OS Command Injection in GPT-SoVITS by RVC-Boss
CVE-2026-63766
9.3CRITICAL
What is CVE-2026-63766?
The GPT-SoVITS product by RVC-Boss contains a critical vulnerability in webui.py, where the ASR, slice, denoise, and uvr5 functions use unsanitized input from Gradio textboxes directly within shell commands executed with shell=True. This flaw allows attackers to exploit path parameters and inject malicious shell metacharacters, leading to arbitrary command execution as the server process user, without requiring authentication.
Affected Version(s)
GPT-SoVITS 0 <= 20250606v2pro
