What is CVE-2026-65701?
A path traversal vulnerability exists in SoftVC VITS Singing Voice Conversion, allowing unauthenticated remote attackers to read and exfiltrate arbitrary files via the audio_path field. Users are advised to update to a version beyond commit 730930d to mitigate the risk.
Azərbaycanca: SoftVC VITS Singing Voice Conversion proqramında `audio_path` sahəsi vasitəsilə path traversal zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış uzaqdan hücumçulara serverdəki ixtiyari faylları oxuyub sızdırmağa imkan verir. İstifadəçilərin commit 730930d-dən sonrakı versiyalara yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Is authentication required to exploit CVE-2026-65701?
No, this vulnerability can be exploited by unauthenticated remote attackers.
What can an attacker achieve through CVE-2026-65701?
An attacker can perform path traversal via the audio_path field to read and exfiltrate arbitrary files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.