CVE-2026-63766
GPT-SoVITS OS Command Injection via Web UI
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical OS command injection vulnerability exists in GPT-SoVITS's web UI where unsanitized user input is directly used in shell commands. This could allow unauthenticated attackers to execute arbitrary OS commands on the server. Confirming if this technology is in use is crucial to assess potential exposure.