OS Command Injection in Dromara Skyeye Product by Dromara
CVE-2026-107780
9.3CRITICAL
What is CVE-2026-107780?
An OS command injection vulnerability exists in the Dromara Skyeye along the unauthenticated /post/TtsController/textToSpeech endpoint. By manipulating the format parameter, attackers can inject elements that disrupt PowerShell strings, ultimately allowing execution of arbitrary commands under the Skyeye service account on Windows environments. This vulnerability poses a significant risk to users utilizing the service without proper input validation safeguards.
Affected Version(s)
skyeye 0 <= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
