Executive brief
CosyVoice, a large-scale voice generation and training model, contains a security flaw in its model averaging tool. If a user is tricked into processing a malicious model file, an attacker can execute arbitrary commands on the user's computer. This could lead to a total system takeover, data theft, or the installation of malware.
Technical details
An insecure deserialization vulnerability (CWE-502) exists in the `average_model.py` script of CosyVoice. The root cause is the use of `torch.load()` to process PyTorch checkpoint files (`epoch_*.pt`) without the `weights_only=True` parameter enabled. Because `torch.load()` utilizes the Python `pickle` module by default, it is susceptible to the deserialization of arbitrary Python objects. An attacker can exploit this by crafting a malicious checkpoint file; when a victim attempts to use the model averaging tool on a directory containing this file, the malicious payload is executed. This requires the victim to manually run the tool on the attacker-supplied file.
Affected products
- FunAudioLLM CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e
Timeline
- 2026-05-11: advisory: CVE-2026-31250 published by NVD/MITRE