CVE-2026-31249 | CosyVoice up to 2025-30-21 Pickle make_parquet_list.py torch.load deserialization
A vulnerability, which was classified as critical, has been found in CosyVoice up to 2025-30-21. Affected by this issue is the function torch.load of the file make_parquet_list.py of the component Pickle Module. This manipulation causes deserialization.
This vulnerability is handled as CVE-2026-31249. The attack can only be done within the local network. There is not any exploit available.