CVE-2025-43845 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 change_info_ ckpt_path2 code injection (GHSL-2025-012)
A vulnerability was found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006. It has been classified as very critical. This affects the function change_info_. The manipulation of the argument ckpt_path2 leads to code injection.
This vulnerability is uniquely identified as CVE-2025-43845. It is possible to initiate the attack remotely. There is no exploit available.