Impact
Dromara Skyeye exposes an OS command injection flaw in the unauthenticated /post/TtsController/textToSpeech endpoint. The format parameter is inserted directly into a PowerShell command without proper escaping, allowing an attacker to insert a single quote, break out of the intended command string, and execute arbitrary PowerShell code as the Skyeye service account. Successful exploitation results in full remote code execution with the privileges granted to the service, enabling attackers to alter, exfiltrate, or persist on the host. The weakness is classified as CWE-78.
Affected Systems
The vulnerability affects any installation of Dromara Skyeye that contains the code targeted by commit 003549ae5. The specific component is the text-to-speech controller that processes the /post/TtsController/textToSpeech request. Since no explicit version numbers are provided, all releases of Skyeye that have not applied a subsequent patch to remove the vulnerable code are at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates a very high severity of remote code execution. EPSS data is not available, so an exploit probability cannot be quantified, but the vulnerability is reachable via an unauthenticated network request, which makes exploitation comparatively easy in standard networked environments. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has yet been documented. Attackers would send a crafted request to the vulnerable endpoint, inject malicious payloads through the format parameter, and obtain control over the Windows service running Skyeye.
OpenCVE Enrichment