ACE-Step 1.5 generates complete songs, vocals included, from a text description and optional lyrics. A language model plans the song (structure, lyrics, BPM, key and captions) and a diffusion transformer renders the audio, from 10 seconds to 10 minutes long, with lyrics in more than 50 languages. Beyond text to music it can make covers from existing audio, repaint one section, separate stems, add accompaniment to a vocal track, and train a LoRA on your own songs, which the README puts at 8 songs and about an hour on an RTX 3090.
The selling point is speed on ordinary hardware: under 10 seconds per song on an RTX 3090 by the README's numbers, with the 2B turbo model fitting in under 6 GB of VRAM through quantization and CPU offload, and support for NVIDIA, AMD, Intel and Apple Silicon. The authors place its quality between Suno v4.5 and v5, which is their own claim rather than an independent test. A 4B XL series added in April 2026 raises quality on GPUs with 12 GB or more.
It is co-led by ACE Studio and StepFun, MIT-licensed along with its model weights, and has about 13,000 stars; YouTube walkthroughs present it as a free, local Suno alternative. It ships a Gradio web UI, a REST API and a CLI, and a separate VST3 plugin brings it into music software.
- Repository: github.com/ace-step/ACE-Step-1.5
- Licence: MIT (MIT License)
- Language: Python. Stars: 13K. Forks: 1,670. Last push: Oct 1, 2026.
- Scan: safe, Aug 29, 2026, commit ca1e85f
Who it is for
Musicians, producers and video creators who want backing tracks or song drafts without a subscription, and developers building music features who need a model they can run and fine-tune themselves.
Getting started
1. Install uv (Windows: the README has a PowerShell line)
curl -LsSf https://astral.sh/uv/install.sh | sh2. Clone the repository and install
git clone https://github.com/ACE-Step/ACE-Step-1.5.git && cd ACE-Step-1.5 && uv sync3. Start the web UI; models download on first run (uv run acestep-api starts the REST API on port 8001)
uv run acestep4. Open it in your browser
open http://localhost:7860Python 3.11 or 3.12 is required, and the first launch downloads several gigabytes of model weights. The UI picks a model and offload settings for your VRAM automatically. Portable Windows and macOS packages with dependencies included are linked from the README, and acemusic.ai offers a hosted version if you have no suitable GPU.
Safety scan
We cloned ace-step/ACE-Step-1.5 at commit ca1e85f on Aug 29, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets and no bare-IP URLs across 1,222 files and about 178,000 lines, mostly Python.
- All 18 pattern hits are the same command: astral.sh's uv installer piped to sh. Two are the actual install in install_uv.sh, which the launch scripts call only after asking Install uv now?; the other 16 are echo lines telling you how to install it yourself. The sudo and shell-profile flags on install_uv.sh come from messages it prints, not commands it runs.
- The 12 installer scripts are the Windows, Linux, macOS and ROCm launchers. They check GitHub for a newer commit at startup and ask before updating (CHECK_UPDATE=false turns this off), and fetch PyTorch wheels from download.pytorch.org. External AI hosts in the code (OpenAI, Anthropic, Z.AI, ElevenLabs) are optional providers for lyric and text tasks and for LoRA data preparation, used only with your keys.
- 134 known advisories (1 critical, 63 high). uv.lock has 104, the critical being anyio 4.12.1 over TLS name checks for internationalised domains. 30 sit in a package-lock.json under .claude/skills, a Node helper for a Claude Code skill that is not part of the music app; the rest are repeats in the requirements files for ROCm and Intel GPUs.
- Four workflows, none using pull_request_target; the 4 third-party actions are pinned to tags. Security policy, CodeQL, licence and contributing guide present; no Dependabot. The latest tagged release, 0.1.8, is from May 2026, while the scanned main branch is from August 29.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | 18 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 12 installer scripts (one fetches and runs a remote script; one edits your shell profile; one can call sudo) |
| Committed binaries | None. |
| CI workflows | 4 workflows. None use pull_request_target. 4 of 4 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 22 distinct hosts referenced from source; most often astral.sh, api.openai.com, download.pytorch.org, github.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 134 advisories across 394 pinned packages: 1 critical, 63 high, 44 moderate, 25 low, 1 unrated. .claude/skills/acestep-simplemv/scripts/package-lock.json: 221 packages, 30 advisories; requirements-rocm-linux.txt: 1 packages, 7 advisories; requirements-rocm.txt: 1 packages, 7 advisories; requirements-xpu.txt: 1 packages, 7 advisories; requirements.txt: 11 packages, 18 advisories; uv.lock: 176 packages, 104 advisories. |
| Project hygiene | Has security policy, CodeQL, licence file, contributing guide. Missing automated dependency updates. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Pattern hits (18)
| Where | Rule | Match |
|---|---|---|
| install_uv.sh:58 | download-piped-to-shell | curl -LsSf https://astral.sh/uv/install.sh 2>/dev/null | sh >/dev/null 2>&1 || true |
| install_uv.sh:61 | download-piped-to-shell | curl -LsSf https://astral.sh/uv/install.sh | sh || true |
| install_uv.sh:66 | download-piped-to-shell | wget -qO- https://astral.sh/uv/install.sh 2>/dev/null | sh >/dev/null 2>&1 || true |
| install_uv.sh:68 | download-piped-to-shell | wget -qO- https://astral.sh/uv/install.sh | sh || true |
| install_uv.sh:156 | download-piped-to-shell | log " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_api_server.sh:156 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_api_server.sh:161 | download-piped-to-shell | echo "Please install uv: curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_api_server_macos.sh:230 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_api_server_macos.sh:235 | download-piped-to-shell | echo "Please install uv: curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui.sh:265 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui.sh:274 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_macos.sh:336 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_macos.sh:343 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_macos_manual.sh:390 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_macos_manual.sh:397 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_manual.sh:386 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| start_gradio_ui_manual.sh:395 | download-piped-to-shell | echo " curl -LsSf https://astral.sh/uv/install.sh | sh" |
| test_env_detection.sh:31 | download-piped-to-shell | echo "To install uv, run: curl -LsSf https://astral.sh/uv/install.sh | sh" |
Installer scripts (12)
- install_uv.sh, 164 lines, uses sudo, edits your shell profile, fetches and runs a remote script; talks to astral.sh
- run_api_server.sh, 27 lines
- run_openrouter_api_server.sh, 27 lines
- start_api_server.sh, 274 lines, fetches and runs a remote script; talks to astral.sh, download.pytorch.org
- start_api_server_macos.sh, 304 lines, fetches and runs a remote script; talks to astral.sh
- start_api_server_rocm.sh, 190 lines; talks to download.pytorch.org, pytorch.org, rocm.docs.amd.com
- start_gradio_ui.sh, 400 lines, fetches and runs a remote script; talks to astral.sh, download.pytorch.org
- start_gradio_ui_macos.sh, 423 lines, fetches and runs a remote script; talks to astral.sh
- start_gradio_ui_macos_manual.sh, 477 lines, fetches and runs a remote script; talks to astral.sh
- start_gradio_ui_manual.sh, 474 lines, fetches and runs a remote script; talks to astral.sh
- start_gradio_ui_rocm.sh, 266 lines; talks to download.pytorch.org, pytorch.org, rocm.docs.amd.com
- start_gradio_ui_rocm_manual.sh, 387 lines; talks to download.pytorch.org, pytorch.org, rocm.docs.amd.com
Worst known vulnerabilities (24 of 134)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-82r6-8w77-94w6 | critical | anyio@4.12.1 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |
| GHSA-73wf-gq98-2v4g | high | browserslist@4.28.1 | Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) |
| GHSA-c83g-rgw3-j3cx | high | browserslist@4.28.1 | Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM |
| GHSA-7pqw-9j4j-h8q3 | high | extract-zip@2.0.1 | extract-zip allows arbitrary file writes through symlink archive entries |
| GHSA-jmr9-qjv8-65gv | high | extract-zip@2.0.1 | extract-zip unvalidated symlink path traversal |
| GHSA-4c8g-83qw-93j6 | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-7p8r-x3mc-p8w7 | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-f65p-4m7j-42xc | high | fast-uri@3.1.0 | fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization |
| GHSA-jqff-g426-hqxp | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| GHSA-q3j6-qgpj-74h6 | high | fast-uri@3.1.0 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| GHSA-qw65-cvwx-89v3 | high | fast-uri@3.1.0 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| GHSA-v2hh-gcrm-f6hx | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-v39h-62p7-jpjc | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| GHSA-28wg-ghj8-5hjv | high | nanoid@3.3.11 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | high | nanoid@3.3.11 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-xwg4-73v4-xw9w | high | nanoid@3.3.11 | nanoid: Integer Overflow or Wraparound |
| GHSA-6g55-p6wh-862q | high | postcss@8.5.6 | PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments |
| GHSA-r28c-9q8g-f849 | high | postcss@8.5.6 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure |
| GHSA-5c6j-r48x-rmvq | high | serialize-javascript@6.0.2 | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() |
| GHSA-96hv-2xvq-fx4p | high | ws@8.17.1 | ws: Memory exhaustion DoS from tiny fragments and data chunks |
| GHSA-39mp-8hj3-5c49 | high | gradio@6.2.0 | Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+ |
| GHSA-7hp7-4p35-3cx2 | high | gradio@6.2.0 | Gradio contains a cookie injection vulnerability |
| GHSA-j36p-7w88-g82j | high | gradio@6.2.0 | Gradio FileExplorer preprocess path traversal allows files outside root_dir to reach callbacks |
| GHSA-jmh7-g254-2cq9 | high | gradio@6.2.0 | Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing |
By the numbers
| Stars | 13K |
|---|---|
| Forks | 1,670 |
| Contributors | 84 |
| Commits | 1,410 |
| Open issues | 105 |
| Open pull requests | 57 |
| Releases | 13 |
| Latest release | v0.1.8 |
| Licence | MIT |
| Main language | Python |
| Project age | 1 year |
| Last push | Oct 1, 2026 |
| Tracked files | 1,222 |
| Lines of code | 177.6K |
| Checkout size | 19 MB |
Lines by language: Python 125.3K, Markdown 32.3K, Shell 6,865, JSON 6,129, Batch 4,773, JavaScript 965.
Questions
Is ACE-Step free?
Yes. The code and the published model weights are MIT-licensed, and it runs locally with no account or usage fee. The authors also run acemusic.ai, a hosted version they describe as free, for people without a suitable GPU.
What GPU does ACE-Step 1.5 need?
It runs in as little as 6 GB of VRAM with the 2B turbo model, the planning language model off and CPU offload on. 8 to 16 GB adds the language model; the 4B XL models want 12 GB with offload or 20 GB without. NVIDIA CUDA works best, with AMD ROCm, Intel XPU, Apple Silicon and CPU also supported.
Can I use songs made with ACE-Step commercially?
The MIT licence places no restriction on what you do with the output. The authors ask users to check that generated songs are not too close to existing works, to disclose AI involvement, and to get permission before imitating protected material, and copyright rules for AI-generated music vary by country.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
