← back
CVE-2025-27783

Applio allows arbitrary file write in train.py

CVSS 7.7 HIGHEPSS 1.0%CWE-22
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote code execution. As of time of publication, no known patches are available.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
IAHispano · Applio

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →