CVE-2026-79535: Command Injection
Published Sep 29, 2026
·Updated
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The updateconfig MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
Affected Software
1 affected component
mbailey VoiceMode<=8.10.1
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Which interfaces can introduce the unsafe configuration value?
Both the update_config MCP tool and the "voicemode config set" CLI can write a caller-supplied value to ~/.voicemode/voicemode.env without shell-safe escaping.
2
What does an attacker need to exploit this issue?
The attacker needs the ability to supply a value through update_config or the "voicemode config set" command. The available information does not specify additional authentication or deployment prerequisites.
3
Which versions should be remediated?
mbailey VoiceMode versions 8.10.1 and earlier are affected. The referenced release for the remediation is v8.10.2.