SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65701

CRITICAL · CVSS 9.1 EPSS 0.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability affects the SoftVC VITS Singing Voice Conversion server, allowing unauthenticated remote attackers to exploit a path traversal flaw through the audio_path parameter in POST requests. This can lead to unauthorized reading and exfiltration of arbitrary files from the server, as well as the ability to write .wav files to any location on the filesystem. Organizations utilizing this software should prioritize patching this critical vulnerability to mitigate the risk of data breaches and unauthorized file access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65701
Severity
CRITICAL
CVSS
9.1
EPSS
0.58%

Original NVD Description

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of an unauthenticated POST request to the /wav2wav route. Attackers can pass arbitrary server-side paths verbatim to librosa.load, torchaudio.load, and soundfile.write sinks, causing the server to decode and return file contents via the HTTP response body while also writing attacker-specified .wav files to arbitrary locations on the filesystem.