CVE-2026-107780 is a critical (CVSS 3.1 9.8) unauthenticated OS command injection flaw in Dromara Skyeye's text-to-speech endpoint that lets remote attackers run commands as the Skyeye service account on Windows.
What Is It
The flaw is an OS command injection (CWE-78) in Dromara Skyeye, an open-source project hosted on GitHub. It sits in the /post/TtsController/textToSpeech endpoint, which does not require authentication. The format parameter is handled unsafely. An attacker can add a single quote to format to break out of a PowerShell string and run arbitrary commands. Those commands run as the Skyeye service account on Windows.
VulnCheck disclosed the issue, and NVD published it on 2026-10-08. The NVD record has a "Deferred" status. The references point to the vulnerable code in TtsServiceImpl.java (lines 105–166).
Why It Matters
- No authentication needed: The endpoint is reachable without credentials (PR:N).
- Remote and low complexity: The attack works over the network with low complexity and no user interaction (AV:N/AC:L/UI:N).
- Full impact: Confidentiality, integrity and availability impacts are all rated High.
- Scores: CVSS 3.1 base score is 9.8 (CRITICAL), vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. VulnCheck's secondary CVSS 4.0 score is 9.3 (CRITICAL).
A successful attack gives code execution with whatever privileges the Skyeye service account has on the Windows host.
The CISA KEV catalog has no entry for this CVE, so KEV does not confirm active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."
What's Vulnerable
- Vendor / Product: dromara / skyeye
- Affected versions: Every commit up to and including
003549ae5615bd114ba5bb8ddf6a8e8ead97c321(git versioning) - Platform impact: The description names command execution through PowerShell on Windows
- Package URL:
pkg:github/dromara/skyeye
NVD lists no CPEs for this record.
Patch Status
The source data names no fixed commit, release or vendor patch. It only says versions through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 are affected. There is no CISA KEV entry, so no federal required action or due date applies.
If you run Skyeye, check the upstream repository and GitHub issue #29 for fix progress. Until a fix is confirmed, treat any deployment at or before the affected commit as vulnerable. This matters most where the /post/TtsController/textToSpeech endpoint can be reached from untrusted networks.
Sources
- NVD – CVE-2026-107780
- VulnCheck Advisory – Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech Format Parameter
- CISA – Known Exploited Vulnerabilities Catalog
- GitHub – dromara/skyeye repository
- GitHub – dromara/skyeye Issue #29
- GitHub – Vulnerable code in TtsServiceImpl.java (L105–L166)