CVE-2025-27784 is an arbitrary file read vulnerability affecting Applio voice conversion tool versions 3.2.8-bugfix and prior, specifically within the train.py's export_pth function. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating that an unauthenticated attacker can remotely read arbitrary files on the Applio server with low attack complexity. The potential impact includes unauthorized disclosure of sensitive information and, when combined with blind server-side request forgery, could allow access to internal network files. Currently, there are no known patches, public exploit code (Metasploit, Nuclei, ExploitDB), or evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.8-bugfixCPE matchmatch criteria | cpe:2.3:a:applio:applio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.