CVE-2026-107780: Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter
Published Oct 8, 2026
·Updated
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.
Affected Software
1 affected component
Dromara Skyeye
Event History
Oct 8, 2026
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Skyeye deployments containing commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 are affected when running on Windows and exposing the /post/TtsController/textToSpeech endpoint.
2
Does an attacker need credentials or user interaction to exploit this?
No. The affected endpoint is unauthenticated, and the reported vector requires no privileges or user interaction.
3
What access could an attacker gain after successful exploitation?
An attacker can execute operating-system commands as the Skyeye service account on Windows.