CVE-2025-43842 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 exp_dir1/np7/trainset_dir4/sr2 command injection (GHSL-2025-012)
A vulnerability was found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 and classified as critical. This issue affects some unknown processing. The manipulation of the argument exp_dir1/np7/trainset_dir4/sr2 leads to command injection.
The identification of this vulnerability is CVE-2025-43842. The attack may be initiated remotely. There is no exploit available.