Applio is a voice-synthesis and audio-manipulation application that has emerged as a moderately prominent target in the vulnerability landscape, concentrated in a single product line. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through a consistent pattern of input-handling and data-processing weaknesses—path traversal, unsafe deserialization, server-side request forgery, information exposure, and injection flaws—that reflect the application's role in accepting and processing user-supplied audio and configuration data. Defenders should prioritize patching and monitor this vendor's releases closely given the severity profile; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Applio over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27780CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_information.py. `model_name` in model_information.py takes user | Mar 19, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-27779CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusio | Mar 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-27781CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference.py. `model_file` in inference.py as well as `model_file` in | Mar 19, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-27778CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time o | Mar 19, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-27786CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input and p | Mar 19, 2025 | 9.1 | 25 | NO | NO |
CVE-2025-27783CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio | Mar 19, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-27782CRITICAL Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the App | Mar 19, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-27785HIGH Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to reading arbit | Mar 19, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-27787HIGH Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py takes user input, and passes it | Mar 19, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-27784HIGH Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitra | Mar 19, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Applio.
Media articles that mention a CVE ID that affects a product developed by Applio — matched by CVE ID, not by vendor name.