NA - CVE-2025-27777 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) in `model_download.py` (line 195 in 3.2.7). The blind SSRF allows for sending...
NA - CVE-2025-27778 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a...
NA - CVE-2025-27779 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from...
NA - CVE-2025-27780 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user-supplied input...
NA - CVE-2025-27781 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in tts.py take...
NA - CVE-2025-27782 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the Applio server. It...
NA - CVE-2025-27783 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio server. It can...
NA - CVE-2025-27784 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on...
NA - CVE-2025-27785 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbitrary files...
NA - CVE-2025-27786 - Applio is a voice conversion tool. Versions...
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input and passes it to...