CVE-2026-63766 | RVC-Boss GPT-SoVITS up to 20250606v2pro WebUI webui.py ASR/slice/denoise/uvr5 path os command injection

SecurityVulns

A vulnerability was found in RVC-Boss GPT-SoVITS up to 20250606v2pro. It has been classified as critical. The affected element is the function ASR/slice/denoise/uvr5 of the file webui.py of the component WebUI. This manipulation of the argument path causes os command injection.

The identification of this vulnerability is CVE-2026-63766. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More