CRITICAL 9.8 CVE-2026-107780 Published 8 Oct 2026

Dromara Skyeye Text-to-Speech Endpoint Command Injection Vulnerability

Worried this affects your website?

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter.

  • Affected versions: through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
  • Attackers can inject a single quote into format to break out of the PowerShell string.
  • Impact: command execution as the Skyeye service account on Windows.

Reference: CVE-2026-107780 on NVD

← Back to Security News