CVE-2025-27778

Severity CVSS v4.0:
HIGH
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
19/03/2025
Last modified:
01/08/2025

Description

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py`. The issue can lead to remote code execution. As of time of publication, a fix is available on the `main` branch of the Applio repository but not attached to a numbered release.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:applio:applio:*:*:*:*:*:*:*:* 3.2.8-bugfix (including)