CVE-2025-43849 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 process_ckpt.py merge ckpt_a/cpkt_b deserialization (GHSL-2025-012)
A vulnerability classified as very critical has been found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006. Affected is the function merge of the file process_ckpt.py. The manipulation of the argument ckpt_a/cpkt_b leads to deserialization.
This vulnerability is traded as CVE-2025-43849. It is possible to launch the attack remotely. There is no exploit available.