Description
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution on the Windows Skyeye service account
Action: Immediate Patch
AI Analysis

Impact

Dromara Skyeye exposes an OS command injection flaw in the unauthenticated /post/TtsController/textToSpeech endpoint. The format parameter is inserted directly into a PowerShell command without proper escaping, allowing an attacker to insert a single quote, break out of the intended command string, and execute arbitrary PowerShell code as the Skyeye service account. Successful exploitation results in full remote code execution with the privileges granted to the service, enabling attackers to alter, exfiltrate, or persist on the host. The weakness is classified as CWE-78.

Affected Systems

The vulnerability affects any installation of Dromara Skyeye that contains the code targeted by commit 003549ae5. The specific component is the text-to-speech controller that processes the /post/TtsController/textToSpeech request. Since no explicit version numbers are provided, all releases of Skyeye that have not applied a subsequent patch to remove the vulnerable code are at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates a very high severity of remote code execution. EPSS data is not available, so an exploit probability cannot be quantified, but the vulnerability is reachable via an unauthenticated network request, which makes exploitation comparatively easy in standard networked environments. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has yet been documented. Attackers would send a crafted request to the vulnerable endpoint, inject malicious payloads through the format parameter, and obtain control over the Windows service running Skyeye.

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Skyeye to a version that contains the fix for the format parameter sanitization.
  • If an upgrade is not immediately possible, limit access to the /post/TtsController/textToSpeech endpoint by adding authentication, placing it behind a firewall, or restricting it to trusted IP ranges.
  • Sanitize or validate the format parameter so that it accepts only safe, expected characters and never includes quote characters; alternatively, refactor the code to use parameterized command execution rather than embedding user data in PowerShell commands.

Generated by OpenCVE AI on October 8, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.
Title Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T20:15:55.304Z

Reserved: 2026-10-08T20:02:30.752Z

Link: CVE-2026-107780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T21:17:52.940

Modified: 2026-10-08T21:27:15.010

Link: CVE-2026-107780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')