Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
History

Fri, 01 Aug 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Applio
Applio applio
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:applio:applio:*:*:*:*:*:*:*:*
Vendors & Products Applio
Applio applio
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 20 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 20:45:00 +0000

Type Values Removed Values Added
Description Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_pth` function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
Title Applio allows arbitrary file read in train.py export_pth function
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-20T19:14:46.029Z

Reserved: 2025-03-06T18:06:54.461Z

Link: CVE-2025-27784

cve-icon Vulnrichment

Updated: 2025-03-20T19:14:41.104Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-19T21:15:40.523

Modified: 2025-08-01T16:24:06.653

Link: CVE-2025-27784

cve-icon Redhat

No data.