Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
History

Wed, 19 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 20:45:00 +0000

Type Values Removed Values Added
Description Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
Title Applio allows arbitrary file read in train.py export_index function
Weaknesses CWE-200
CWE-22
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-19T20:35:10.662Z

Updated: 2025-03-19T20:47:30.839Z

Reserved: 2025-03-06T18:06:54.461Z

Link: CVE-2025-27785

cve-icon Vulnrichment

Updated: 2025-03-19T20:46:54.447Z

cve-icon NVD

Status : Received

Published: 2025-03-19T21:15:40.650

Modified: 2025-03-19T21:15:40.650

Link: CVE-2025-27785

cve-icon Redhat

No data.