CosyVoice Insecure Deserialization Vulnerability in gRPC Server Component

Vulnerability

A vulnerability allowing insecure deserialization has been identified in CosyVoice, specifically in the gRPC server component. This issue arises because the application loads the speech synthesis model from a user-specified directory using torch.load() without enabling the weights_only=True security parameter. As a result, arbitrary Python objects can be deserialized via the pickle module. An attacker could exploit this vulnerability by placing malicious model files in the designated directory. When the gRPC server is started with this directory, the malicious code is executed on the victim's system during the server's initialization phase.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the victim's system.

Reproduction

To reproduce this vulnerability, upload a malicious model file that exploits the insecure deserialization into a directory. Start the CosyVoice gRPC server and point it to the directory containing the malicious model file. During the server initialization, the malicious code will be executed, demonstrating the vulnerability.

Added: May 11, 2026, 5:51 PM
Updated: May 11, 2026, 5:51 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.7
remediation
0.0
relevance
8.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.