Ghostwire

CVE-2026-107780: Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in...

CRITICAL CVSS 0.0 EPSS 2.06%

Published: October 8, 2026 | Last Modified: October 8, 2026

Description

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Moderate — 2.06% (81th percentile)

Measurable exploitation probability. Should be patched in the normal vulnerability management cycle.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References