Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows. | |
| Title | Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:15:55.304Z
Reserved: 2026-10-08T20:02:30.752Z
Link: CVE-2026-107780
No data.
Status : Deferred
Published: 2026-10-08T21:17:52.940
Modified: 2026-10-08T21:27:15.010
Link: CVE-2026-107780
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:30:18Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')