Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in infer.py
. The issue can lead to remote code execution. As of time of publication, a fix is available on the main
branch of the Applio repository but not attached to a numbered release.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Applio | Applio | * | 3.2.8-bugfix (including) |