An unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.
PoC
GPT-SoVITS through 20250606v2pro +1
command-injection
rce
web-vulnerability
ai/ml-model
cve
1r
2t
1c
2i
updated