CVE-2025-27786CRITICAL 9.1EPSS p37.5%

CVE-2025-27786CVE-2025-27786

Description

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input and passes it to `run_tts_script` function in core.py, which checks if the path in `output_tts_path` exists, and if yes, removes that path, which leads to arbitrary file removal. As of time of publication, no known patches are available.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.48% probability of exploitation · percentile 37.5% · 2026-06-19T12:03:05Z
Published2025-03-19
Last modified2025-08-01

Underlying weaknesses· 1

CWE-22

References

  1. https://github.com/IAHispano/Applio/blob/29b4a00e4be209f9aac51cd9ccffcc632dfb2973/core.py#L329
  2. https://github.com/IAHispano/Applio/blob/29b4a00e4be209f9aac51cd9ccffcc632dfb2973/tabs/tts/tts.py#L133
  3. https://securitylab.github.com/advisories/GHSL-2024-341_GHSL-2024-353_Applio/

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-27782
CVE
CVE-2025-27783
CVE
CVE-2025-27778
CVE
CVE-2025-27781
CVE
CVE-2025-27780
CVE
CVE-2025-27779
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.