CVE-2026-107780 | Dromara Skyeye TextToSpeech textToSpeech format os command injection
A vulnerability classified as critical has been found in Dromara Skyeye. This impacts an unknown function of the file /post/TtsController/textToSpeech of the component TextToSpeech. The manipulation of the argument format leads to os command injection.
This vulnerability is traded as CVE-2026-107780. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More