Tag
critical
advisory
CVE-2026-65701 - SoftVC VITS Singing Voice Conversion Path Traversal Vulnerability
1 rule 4 TTPs 1 CVEA path traversal vulnerability exists in the full-song inference server of SoftVC VITS Singing Voice Conversion, affecting versions through commit 730930d, allowing unauthenticated remote attackers to read and exfiltrate arbitrary files by manipulating the 'audio_path' field in an unauthenticated POST request to the '/wav2wav' route.
VITS Singing Voice Conversion
path-traversal
file-exfiltration
arbitrary-file-write
web-application
1r
4t
1c
critical
advisory
gemini-mcp-tool Vulnerable to OS Command Injection and File Exfiltration (CVE-2026-0755)
2 rules 3 TTPsA critical vulnerability, CVE-2026-0755, in npm's gemini-mcp-tool package allows for OS command injection on Windows systems due to improper handling of unquoted cmd.exe metacharacters, and arbitrary local file exfiltration via the @file parser when processing untrusted prompt input, leading to potential remote code execution and sensitive data compromise.
gemini-mcp-tool
command-injection
file-exfiltration
npm
cli-tool
web-vulnerability
2r
3t