NPM · JULY 2026 · EARLY WARNING

GPT-SoVITS npm Package OS Command Injection Vulnerability Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-63766Severity: CRITICAL

The GPT-SoVITS npm package through 20250606v2pro is under investigation for containing an OS command injection vulnerability that could allow attackers to execute arbitrary OS commands.

What happened

An OS command injection vulnerability has been reported in the GPT-SoVITS npm package through version 20250606v2pro. The vulnerability, tracked as CVE-2026-63766, is located in the webui.py file where unsanitized Gradio textbox values are interpolated directly into shell commands executed with shell=True. This allows attackers to inject shell metacharacters through path parameters and execute arbitrary OS commands as the server process user without authentication.

The vulnerability affects the ASR, slice, denoise, and uvr5 functions within the package. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Users of the GPT-SoVITS package are advised to monitor for updates and consider upgrading to a patched version as soon as it becomes available.

It is recommended to review server logs for any suspicious activity that may indicate exploitation of this vulnerability. Further details and updates should be obtained from the primary sources, as the situation is still under investigation.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gpt-sovits is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats