๐Ÿ” CVE Alert

CVE-2026-73660

UNKNOWN 0.0

FreePBX: Authenticated TTS AGI Command Injection Through TTS Name

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside agi-bin/propolys-tts.agi. The TTS destination name reaches a raw shell-command execution path, allowing arbitrary operating-system command execution as the asterisk service user. This issue is fixed in versions 16.0.6 and 17.0.5.4.

CWE CWE-78
Vendor freepbx
Product tts
Published Aug 13, 2026
Last Updated Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for freepbx tts

Be the first to know when new unknown vulnerabilities affecting freepbx tts are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreePBX / tts
< 16.0.6 >= 17.0.1, < 17.0.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-hg3v-m857-mvw9 github.com: https://github.com/FreePBX/tts/commit/37cf0dd3e9ceb4a32e09a2fca6a145320245c0a0 github.com: https://github.com/FreePBX/tts/commit/4057410439e66d8be2b47c6358de5fab498bbc21