๐Ÿ” CVE Alert

CVE-2026-107780

CRITICAL 9.8

Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.

CWE CWE-78
Vendor dromara
Product skyeye
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for dromara skyeye

Be the first to know when new critical vulnerabilities affecting dromara skyeye are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

dromara / skyeye
0 โ‰ค 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dromara/skyeye/issues/29 github.com: https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-promote/skyeye-common/src/main/java/com/skyeye/common/service/impl/TtsServiceImpl.java#L105-L166 github.com: https://github.com/dromara/skyeye vulncheck.com: https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-os-command-injection-via-texttospeech-format-parameter

Credits

Ikram-4