CVE-2026-63766 is an OS command injection vulnerability in GPT-SoVITS through version 20250606v2pro. The flaw is present in webui.py, where the ASR, slice, denoise, and uvr5 functions incorporate user-controlled Gradio textbox input directly into shell command strings and execute them with shell=True. Because path-related parameters are not sanitized or safely passed as structured arguments, an attacker can inject shell metacharacters and alter the intended command flow. The issue is remotely exploitable without authentication and results in arbitrary operating system command execution in the security context of the server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-63766 affecting GPT-SoVITS webui.py. It contains two files: a README describing the vulnerability, exploitation method, and examples; and exploit.py, the actual exploit entry point. The exploit uses gradio_client to connect to a target GPT-SoVITS Gradio web UI and call the /open_asr API. Its core capability is unauthenticated remote OS command execution by placing an operator-controlled shell command inside $() and supplying that string as the asr_opt_dir argument. According to the repository, the vulnerable server later interpolates this value into a shell command executed with shell=True, causing command substitution to run as the web UI process user. The exploit is operational rather than a mere PoC because it accepts arbitrary attacker commands and can be used for file writes or reverse shells, though it does not include advanced payload management. Fingerprintable target indicators include the default HTTP service on port 9874 and the /config endpoint, which can reveal Gradio API names such as open_asr. The exploit does not perform vulnerability verification beyond invoking the API; it simply delivers the payload and prints the returned server response.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.