CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107780
CRITICALCVSS 9.8NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and e
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107910 HIGH 8.1
- CVE-2026-107911 HIGH 7.5
- CVE-2026-7826 CRITICAL 9.1
- CVE-2026-7827 HIGH 8.1
- CVE-2026-5759 CRITICAL 9.8
- CVE-2026-107888 MEDIUM 5.1
- CVE-2026-88131 CRITICAL 9.8
- CVE-2026-56857 CRITICAL 9.8
- CVE-2026-107729 MEDIUM 5.5
- CVE-2026-107730 MEDIUM 5.5