{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/ai/ml-model/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-63766"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GPT-SoVITS through 20250606v2pro"],"_cs_severities":["critical"],"_cs_tags":["command-injection","rce","web-vulnerability","ai/ml-model","cve"],"_cs_type":"advisory","_cs_vendors":["RVC-Boss"],"content_html":"\u003cp\u003eGPT-SoVITS, a platform for text-to-speech and voice cloning, is affected by a critical OS command injection vulnerability, CVE-2026-63766, impacting versions through 20250606v2pro. This flaw resides in the \u003ccode\u003ewebui.py\u003c/code\u003e component, specifically within the \u003ccode\u003eASR\u003c/code\u003e, \u003ccode\u003eslice\u003c/code\u003e, \u003ccode\u003edenoise\u003c/code\u003e, and \u003ccode\u003euvr5\u003c/code\u003e functions. These functions insecurely interpolate unsanitized Gradio textbox values directly into shell commands executed with \u003ccode\u003eshell=True\u003c/code\u003e. An unauthenticated attacker can exploit this by injecting shell metacharacters (e.g., semicolons, pipes, ampersands) through path parameters in HTTP requests. Successful exploitation grants the attacker arbitrary OS command execution privileges, running commands as the user associated with the GPT-SoVITS server process, potentially leading to full system compromise. The vulnerability has a CVSS v3.1 base score of 9.8, indicating a critical severity and ease of exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a specially crafted HTTP request to the vulnerable GPT-SoVITS web interface.\u003c/li\u003e\n\u003cli\u003eThe request targets a susceptible function within \u003ccode\u003ewebui.py\u003c/code\u003e, such as \u003ccode\u003eASR\u003c/code\u003e, \u003ccode\u003eslice\u003c/code\u003e, \u003ccode\u003edenoise\u003c/code\u003e, or \u003ccode\u003euvr5\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker injects shell metacharacters (e.g., \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e|\u003c/code\u003e, \u003ccode\u003e\u0026amp;\u0026amp;\u003c/code\u003e, \u003ccode\u003e$()\u003c/code\u003e) into a path parameter or Gradio textbox input that is not properly sanitized.\u003c/li\u003e\n\u003cli\u003eThe vulnerable Python code in \u003ccode\u003ewebui.py\u003c/code\u003e interpolates the unsanitized malicious input directly into a system command executed using a shell (e.g., \u003ccode\u003esubprocess.run(..., shell=True)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe operating system's shell processes the combined command string, interpreting the injected metacharacters as distinct commands.\u003c/li\u003e\n\u003cli\u003eThe attacker's arbitrary commands are executed on the server, typically with the privileges of the GPT-SoVITS application user.\u003c/li\u003e\n\u003cli\u003eThe attacker gains remote code execution, potentially enabling persistent access, data exfiltration, or further lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63766 results in unauthenticated remote code execution (RCE) on the server hosting GPT-SoVITS. Given the CVSS v3.1 score of 9.8 (Critical), this vulnerability allows for complete compromise of confidentiality, integrity, and availability of the affected system. Attackers can execute any command with the privileges of the server process, enabling them to install backdoors, steal sensitive data, modify system configurations, or deploy further malicious payloads. Organizations using GPT-SoVITS for AI/ML model inference or development could face significant data breaches, operational disruption, and reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch GPT-SoVITS to a version beyond 20250606v2pro to remediate CVE-2026-63766 immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect exploitation attempts targeting \u003ccode\u003ewebui.py\u003c/code\u003e with shell metacharacters.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs and application logs for unusual HTTP requests to \u003ccode\u003ewebui.py\u003c/code\u003e or unexpected command execution originating from the GPT-SoVITS process.\u003c/li\u003e\n\u003cli\u003eImplement strong input validation for all user-supplied data, especially in web applications, to prevent similar command injection vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T20:18:01Z","date_published":"2026-07-20T20:18:01Z","id":"https://feed.craftedsignal.io/briefs/2026-07-gpt-sovits-os-command-injection/","summary":"An unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.","title":"CVE-2026-63766: Unauthenticated OS Command Injection in GPT-SoVITS webui.py","url":"https://feed.craftedsignal.io/briefs/2026-07-gpt-sovits-os-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Ai/Ml-Model","version":"https://jsonfeed.org/version/1.1"}