CRITICAL
9.8 CVE-2026-107780 Published 8 Oct 2026
Dromara Skyeye Text-to-Speech Endpoint Command Injection Vulnerability
Worried this affects your website?
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter.
- Affected versions: through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
- Attackers can inject a single quote into format to break out of the PowerShell string.
- Impact: command execution as the Skyeye service account on Windows.
Reference: CVE-2026-107780 on NVD
← Back to Security News