CVE-2025-43848 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 process_ckpt.py change_info ckpt_path0 deserialization (GHSL-2025-012)
A vulnerability was found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006. It has been rated as very critical. This issue affects the function change_info of the file process_ckpt.py. The manipulation of the argument ckpt_path0 leads to deserialization.
The identification of this vulnerability is CVE-2025-43848. The attack may be initiated remotely. There is no exploit available.