Executive brief
CosyVoice, a large-scale voice generation and AI model platform, is vulnerable to a security flaw in how it handles model files. If a user is tricked into loading a malicious AI model file from a specific directory, an attacker can execute arbitrary commands on the underlying system. This could lead to a total compromise of the server, theft of sensitive data, or unauthorized access to the organization's infrastructure.
Technical details
An insecure deserialization vulnerability (CWE-502) exists in CosyVoice through commit 6e01309. The vulnerability is located in the model loading process where the application utilizes the `torch.load()` function to process PyTorch model files (.pt). Because the function is called without the `weights_only=True` parameter, it defaults to using the Python Pickle module for deserialization. An attacker can craft a malicious model directory containing .pt files with embedded pickle payloads. When a user specifies this directory via the `--model_dir` argument or through the web interface, the payload is executed. This results in arbitrary code execution with the privileges of the user running the CosyVoice process.
Affected products
- FunAudioLLM CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e
Timeline
- 2026-05-12: advisory: NVD publication date