{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/softvc/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-65701"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VITS Singing Voice Conversion (through commit 730930d)"],"_cs_severities":["critical"],"_cs_tags":["path-traversal","file-exfiltration","arbitrary-file-write","web-application"],"_cs_type":"advisory","_cs_vendors":["SoftVC"],"content_html":"\u003cp\u003eA critical path traversal vulnerability, tracked as CVE-2026-65701, has been identified in the full-song inference server of SoftVC VITS Singing Voice Conversion, specifically affecting versions up to and including commit 730930d. This flaw permits unauthenticated remote attackers to exploit the server by manipulating the \u003ccode\u003eaudio_path\u003c/code\u003e field within an HTTP POST request directed at the \u003ccode\u003e/wav2wav\u003c/code\u003e route. By supplying attacker-controlled filesystem paths, threat actors can force the application to read and exfiltrate arbitrary files, returning their contents via the HTTP response body. Furthermore, the vulnerability enables the writing of attacker-specified \u003ccode\u003e.wav\u003c/code\u003e files to arbitrary locations on the server's filesystem, leveraging functions like \u003ccode\u003elibrosa.load\u003c/code\u003e, \u003ccode\u003etorchaudio.load\u003c/code\u003e, and \u003ccode\u003esoundfile.write\u003c/code\u003e. This vulnerability presents a significant risk for data exfiltration and potential arbitrary file write leading to further compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker identifies a SoftVC VITS Singing Voice Conversion instance exposing the vulnerable full-song inference server.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the \u003ccode\u003e/wav2wav\u003c/code\u003e route of the application.\u003c/li\u003e\n\u003cli\u003eThe request includes an \u003ccode\u003eaudio_path\u003c/code\u003e parameter containing path traversal sequences (e.g., \u003ccode\u003e../../../../etc/passwd\u003c/code\u003e) to specify an arbitrary file on the server's filesystem.\u003c/li\u003e\n\u003cli\u003eThe vulnerable server receives the request and passes the attacker-controlled \u003ccode\u003eaudio_path\u003c/code\u003e value directly to file loading functions such as \u003ccode\u003elibrosa.load\u003c/code\u003e or \u003ccode\u003etorchaudio.load\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application reads the content of the arbitrary file (e.g., \u003ccode\u003e/etc/passwd\u003c/code\u003e) from the server's filesystem.\u003c/li\u003e\n\u003cli\u003eThe content of the accessed file is then decoded and included in the HTTP response body, effectively exfiltrating the data to the attacker.\u003c/li\u003e\n\u003cli\u003eAlternatively, the attacker can specify a writable arbitrary path in the \u003ccode\u003eaudio_path\u003c/code\u003e parameter, causing \u003ccode\u003esoundfile.write\u003c/code\u003e to create a \u003ccode\u003e.wav\u003c/code\u003e file at the specified location with attacker-controlled content.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65701 can lead to severe consequences for affected organizations. Attackers can read sensitive configuration files, user data, source code, or other proprietary information directly from the server's filesystem, leading to unauthorized disclosure and data exfiltration. The ability to write arbitrary \u003ccode\u003e.wav\u003c/code\u003e files to any location on the filesystem can also be abused for denial-of-service, planting malicious executables, or achieving persistence by writing web shells in publicly accessible directories. The high CVSS score of 9.1 reflects the critical nature of this vulnerability, indicating potential for complete compromise of confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-65701\u003c/strong\u003e: Immediately update SoftVC VITS Singing Voice Conversion to a version beyond commit 730930d to remediate CVE-2026-65701.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy the Sigma rule\u003c/strong\u003e to your SIEM to detect attempts at exploiting this vulnerability.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEnable web server access logging\u003c/strong\u003e for the \u003ccode\u003ewebserver\u003c/code\u003e category to ensure HTTP POST requests and their parameters to \u003ccode\u003e/wav2wav\u003c/code\u003e are recorded for detection and forensics.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T18:22:56Z","date_published":"2026-07-23T18:22:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-softvc-vits-path-traversal/","summary":"A path traversal vulnerability exists in the full-song inference server of SoftVC VITS Singing Voice Conversion, affecting versions through commit 730930d, allowing unauthenticated remote attackers to read and exfiltrate arbitrary files by manipulating the 'audio_path' field in an unauthenticated POST request to the '/wav2wav' route.","title":"CVE-2026-65701 - SoftVC VITS Singing Voice Conversion Path Traversal Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-softvc-vits-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - SoftVC","version":"https://jsonfeed.org/version/1.1"}