Junglewise Threat Intelligence

CVE-2026-63766: RVC-Boss GPT-SoVITS OS command injection in webui.py

CVE-2026-63766 · Severity: critical · CVSS 9.8 · Published 2026-07-20

Executive brief

GPT-SoVITS, an open-source AI voice cloning and speech synthesis tool, contains a critical security flaw in its web interface. An attacker can remotely execute malicious commands on the server hosting the software by entering specially crafted text into directory path fields. Because the interface lacks authentication by default, this could lead to a complete takeover of the server and access to any data stored on it.

Technical details

An OS command injection vulnerability exists in GPT-SoVITS through version 20250606v2pro within the `webui.py` component. The application uses `subprocess.Popen` with `shell=True` to execute various processing tasks (ASR, slice, denoise, and uvr5) while interpolating unsanitized input from Gradio textboxes into the command string. Specifically, the `clean_path` utility fails to strip shell metacharacters like semicolons, backticks, or command substitution syntax. Since the WebUI binds to all interfaces (0.0.0.0) without authentication by default, a remote attacker can inject shell commands via path parameters to achieve arbitrary code execution as the user running the server process.

Affected products

  • RVC-Boss GPT-SoVITS through 20250606v2pro

Timeline

  • 2026-06-12: disclosed: Issue reported on GitHub by researcher George Chen
  • 2026-07-20: advisory: NVD and VulnCheck published advisory details

References