OS Command Injection in Dromara Skyeye Product by Dromara
CVE-2026-107780

9.3CRITICAL

Key Information:

Vendor

Dromara

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107780?

An OS command injection vulnerability exists in the Dromara Skyeye along the unauthenticated /post/TtsController/textToSpeech endpoint. By manipulating the format parameter, attackers can inject elements that disrupt PowerShell strings, ultimately allowing execution of arbitrary commands under the Skyeye service account on Windows environments. This vulnerability poses a significant risk to users utilizing the service without proper input validation safeguards.

Affected Version(s)

skyeye 0 <= 003549ae5615bd114ba5bb8ddf6a8e8ead97c321

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.