Ghostwire

CVE-2026-65701: SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song...

CRITICAL CVSS 0.0 EPSS 0.58%

Published: July 23, 2026 | Last Modified: July 24, 2026

Description

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated POST request to the /wav2wav route. Attackers can pass arbitrary server-side paths verbatim to librosa.load, torchaudio.load, and soundfile.write sinks, causing the server to decode and return file contents via the HTTP response body while also writing attacker-specified .wav files to arbitrary locations on the filesystem.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.58% (44th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References