inspiremusic@0.0.1.dev0 vulnerabilities

InspireMusic: A Fundamental Music, Song and Audio Generation Framework and Toolkits

  • latest version

    0.0.1.dev0

  • first published

    4 months ago

  • latest version published

    4 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the inspiremusic package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Deserialization of Untrusted Data

    inspiremusic is an InspireMusic: A Fundamental Music, Song and Audio Generation Framework and Toolkits

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the load function in the file cli/model.py. An attacker can manipulate internal data structures by providing malicious input to the deserialization process. This is only exploitable if the attacker has local access to execute the function with crafted data.

    How to fix Deserialization of Untrusted Data?

    A fix was pushed into the master branch but not yet published.

    [0,)