CVE-2026-63766
CRITICALGPT-SoVITS 20250606v2pro OS Command Injection via webui.py
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-63766. PoCs published by 0xdak.
AI-analyzed exploit summary This exploit targets an unauthenticated OS command injection vulnerability in GPT-SoVITS's Gradio web UI (CVE-2026-63766). The exploit leverages unsanitized path values in audio-processing helpers, injecting shell commands via command substitution in the `asr_opt_dir` parameter.
Description
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.
Exploits (1)
This exploit targets an unauthenticated OS command injection vulnerability in GPT-SoVITS's Gradio web UI (CVE-2026-63766). The exploit leverages unsanitized path values in audio-processing helpers, injecting shell commands via command substitution in the `asr_opt_dir` parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H