CVE-2026-31232: n/a
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the security-restrictive weights_only=True parameter. This allows the deserialization of arbitrary Python objects via the Pickle module. An attacker can exploit this by providing a maliciously crafted model directory containing .pt files with embedded pickle payloads. When a victim loads this directory using CosyVoice's web interface, the malicious payload is executed, leading to remote code execution on the victim's system.
AI Analysis
Technical Summary
The CosyVoice project contains an insecure deserialization vulnerability (CWE-502) in its model loading mechanism. Specifically, when loading model files from a user-specified directory via the --model_dir argument, the code calls torch.load() without the security-restrictive weights_only=True parameter. This omission permits deserialization of arbitrary Python objects through Pickle embedded in .pt files. An attacker can exploit this by supplying a crafted model directory containing malicious .pt files. When these files are loaded via CosyVoice's web interface, the embedded payload executes, resulting in remote code execution on the victim system. The vulnerability is publicly known as CVE-2026-31232 with a CVSS 3.1 score of 8.8, indicating high impact on confidentiality, integrity, and availability. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation leads to remote code execution on the victim's system when a malicious model file is loaded. This compromises confidentiality, integrity, and availability of the affected system. The vulnerability is exploitable remotely without privileges but requires user interaction to load the malicious model directory. No known exploits in the wild have been reported so far.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid loading model files from untrusted or unauthenticated sources. Implement manual validation or sandboxing of model files before loading. Monitor official CosyVoice channels for updates or patches addressing this insecure deserialization issue.
CVE-2026-31232: n/a
Description
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the security-restrictive weights_only=True parameter. This allows the deserialization of arbitrary Python objects via the Pickle module. An attacker can exploit this by providing a maliciously crafted model directory containing .pt files with embedded pickle payloads. When a victim loads this directory using CosyVoice's web interface, the malicious payload is executed, leading to remote code execution on the victim's system.
CVSS v3.1
Score 8.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The CosyVoice project contains an insecure deserialization vulnerability (CWE-502) in its model loading mechanism. Specifically, when loading model files from a user-specified directory via the --model_dir argument, the code calls torch.load() without the security-restrictive weights_only=True parameter. This omission permits deserialization of arbitrary Python objects through Pickle embedded in .pt files. An attacker can exploit this by supplying a crafted model directory containing malicious .pt files. When these files are loaded via CosyVoice's web interface, the embedded payload executes, resulting in remote code execution on the victim system. The vulnerability is publicly known as CVE-2026-31232 with a CVSS 3.1 score of 8.8, indicating high impact on confidentiality, integrity, and availability. There is no vendor advisory or patch available at this time.
Potential Impact
Successful exploitation leads to remote code execution on the victim's system when a malicious model file is loaded. This compromises confidentiality, integrity, and availability of the affected system. The vulnerability is exploitable remotely without privileges but requires user interaction to load the malicious model directory. No known exploits in the wild have been reported so far.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid loading model files from untrusted or unauthenticated sources. Implement manual validation or sandboxing of model files before loading. Monitor official CosyVoice channels for updates or patches addressing this insecure deserialization issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-03-09T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a036531cbff5d861008c1ae
Added to database: 05/12/2026, 17:36:49 UTC
Last enriched: 05/20/2026, 18:40:16 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.