Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-63766: GPT-SoVITS through 20250606v2pro: Unsecured OS Command Execution

CVE-2026-63766 CVE-2026-63766
Summary

GPT-SoVITS, a text-to-image model, is at risk if attackers can inject malicious commands through its web interface. This could allow unauthorized access to the system and potentially lead to data theft or disruption. Users should update to a secure version to prevent exploitation.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rvc-boss gpt-sovits <= 20250606v2pro
Original title
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
Original description
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-78 OS Command Injection
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 20 Jul 2026