CVE-2025-43846 | RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006 process_ckpt.py ckpt_path1 deserialization (GHSL-2025-012)
A vulnerability was found in RVC-Project Retrieval-based-Voice-Conversion-WebUI up to 2.2.231006. It has been declared as very critical. This vulnerability affects unknown code of the file process_ckpt.py. The manipulation of the argument ckpt_path1 leads to deserialization.
This vulnerability was named CVE-2025-43846. The attack can be initiated remotely. There is no exploit available.