Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dromara
Dromara skyeye |
|
| Vendors & Products |
Dromara
Dromara skyeye |
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows. | |
| Title | Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:15:55.304Z
Reserved: 2026-10-08T20:02:30.752Z
Link: CVE-2026-107780
No data.
Status : Deferred
Published: 2026-10-08T21:17:52.940
Modified: 2026-10-08T21:27:15.010
Link: CVE-2026-107780
No data.
OpenCVE Enrichment
Updated: 2026-10-09T08:03:29Z
Weaknesses