CVE-2025-43847 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 process_ckpt.py extract_small_model ckpt_path2 deserialization (GHSL-2025-012)
A vulnerability was found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 and classified as very critical. Affected by this issue is the function extract_small_model of the file process_ckpt.py. The manipulation of the argument ckpt_path2 leads to deserialization.
This vulnerability is handled as CVE-2025-43847. The attack may be launched remotely. There is no exploit available.