Rvc Boss maintains a niche audio-synthesis and voice-conversion web interface product that has surfaced vulnerabilities despite its specialized scope. The exposure has been limited to its GPT-SoVITS WebUI application; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rvc Boss over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49836CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. pat | Jul 15, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-49839CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choo | Jul 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-49838CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPreDeEcho. The mod | Jul 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-49837CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_cho | Jul 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-49841CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in process_ckpt.py. The SoVITS_d | Jul 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-49840CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in inference_webui.py. The GPT_d | Jul 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-49834CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_denoise function. den | Jul 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-49833CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the webui.py open_slice function. s | Jul 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-49835CRITICAL GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_asr function. asr_inp | Jul 15, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rvc Boss.
Media articles that mention a CVE ID that affects a product developed by Rvc Boss — matched by CVE ID, not by vendor name.