Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
History

Thu, 20 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 20:45:00 +0000

Type Values Removed Values Added
Description Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
Title Applio allows arbitrary file read in train.py export_pth function
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-19T20:41:32.140Z

Updated: 2025-03-20T19:14:46.029Z

Reserved: 2025-03-06T18:06:54.461Z

Link: CVE-2025-27784

cve-icon Vulnrichment

Updated: 2025-03-20T19:14:41.104Z

cve-icon NVD

Status : Received

Published: 2025-03-19T21:15:40.523

Modified: 2025-03-19T21:15:40.523

Link: CVE-2025-27784

cve-icon Redhat

No data.