Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107780 2026-10-08

Dromara Skyeye Unauthenticated OS Command Injection (CVE-2026-107780)

"CVE-2026-107780 is a critical (CVSS 3.1 9.8) unauthenticated OS command injection flaw in Dromara Skyeye's text-to-speech endpoint that lets remote attackers run commands as the Skyeye service account on Windows."

CVE-2026-107780 is a critical (CVSS 3.1 9.8) unauthenticated OS command injection flaw in Dromara Skyeye's text-to-speech endpoint that lets remote attackers run commands as the Skyeye service account on Windows.

What Is It

The flaw is an OS command injection (CWE-78) in Dromara Skyeye, an open-source project hosted on GitHub. It sits in the /post/TtsController/textToSpeech endpoint, which does not require authentication. The format parameter is handled unsafely. An attacker can add a single quote to format to break out of a PowerShell string and run arbitrary commands. Those commands run as the Skyeye service account on Windows.

VulnCheck disclosed the issue, and NVD published it on 2026-10-08. The NVD record has a "Deferred" status. The references point to the vulnerable code in TtsServiceImpl.java (lines 105–166).

Why It Matters

A successful attack gives code execution with whatever privileges the Skyeye service account has on the Windows host.

The CISA KEV catalog has no entry for this CVE, so KEV does not confirm active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."

What's Vulnerable

NVD lists no CPEs for this record.

Patch Status

The source data names no fixed commit, release or vendor patch. It only says versions through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 are affected. There is no CISA KEV entry, so no federal required action or due date applies.

If you run Skyeye, check the upstream repository and GitHub issue #29 for fix progress. Until a fix is confirmed, treat any deployment at or before the affected commit as vulnerable. This matters most where the /post/TtsController/textToSpeech endpoint can be reached from untrusted networks.

Sources