Overview
A critical unauthenticated OS command injection vulnerability, tracked as CVE-2026-107780, affects Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321. The flaw sits in the unauthenticated /post/TtsController/textToSpeech endpoint, where the format parameter is concatenated directly into a PowerShell command string. By submitting a single quote in format, an attacker can break out of the intended string literal and append arbitrary PowerShell commands, achieving unauthenticated remote code execution as the Skyeye service account. The issue carries a CVSS v3.1 score of 9.8 (Critical) and a CVSS v4.0 score of 9.3, published to NVD on October 8, 2026.
Skyeye also bundles a separately-tracked, separately-caused flaw — CVE-2026-107779 — in its embedded xxl-job-admin component. The two bugs were disclosed in the same batch but do not share a root cause; see the note under References.
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-107780 |
| Severity | Critical |
| CVSS v3.1 Score | 9.8 |
| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS v4.0 Score | 9.3 |
| CWE | CWE-78 — Improper Neutralization of Special Elements used in an OS Command |
| Attack Vector | Network |
| Attack Complexity | Low |
| Authentication | None required |
| User Interaction | None |
| Scope | Unchanged |
| Impact (C / I / A) | High / High / High |
| Affected Endpoint | /post/TtsController/textToSpeech (format parameter) |
| Affected Versions | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 |
| Assigned By | NVD / CVE.org |
| Disclosed | October 8, 2026 |
How It Works
The format Parameter
Skyeye's text-to-speech feature exposes /post/TtsController/textToSpeech without any authentication check. The endpoint accepts a block of text to synthesize and a format value that selects the output audio file type. Review of the vulnerable implementation, TtsServiceImpl.java (lines 105–166), shows that the text input has partial sanitization — single quotes in the spoken text are escaped — but the format value is passed through unsanitized and also governs the output file extension, which the public issue tracker additionally flags as a path-handling concern (CWE-22) alongside the command-injection issue (CWE-78).
PowerShell String Concatenation
On Windows deployments, the service shells out via Runtime.getRuntime().exec() to drive the OS's built-in speech synthesis engine and write the result to disk in the requested format. The command line passed to powershell.exe is built by directly concatenating the format value into a single-quoted PowerShell string literal — for example, a construct resembling ...-Format ' + format + '... — rather than passing it as a separate, properly escaped argument.
The Single-Quote Breakout
Because format is never validated against an allow list (such as wav/mp3 only) or escaped before concatenation, an attacker can place a literal apostrophe inside the value to terminate the PowerShell string early. Everything after the injected quote is then parsed by PowerShell as a new statement rather than as string data, letting the attacker append arbitrary commands — for example Invoke-Expression, Start-Process, or an encoded reverse-shell one-liner — onto the same command line.
Command Execution
Because the endpoint requires no credentials and the resulting PowerShell process runs with the privileges of the Skyeye service account, a single unauthenticated HTTP POST is enough to achieve remote code execution. Independent analysis published alongside the public issue also notes that the same unsanitized-format pattern could reach a command-injection path via the say utility on non-Windows builds; the CVE's own description and CVSS scoring center specifically on the Windows/PowerShell path.
Impact Assessment
Who Is At Risk
- Any organization running an unpatched Dromara Skyeye deployment at or before the vulnerable commit, where the host running the TTS feature is network-reachable.
- Internet-facing or broadly LAN-accessible Skyeye instances are at the highest risk, since the endpoint requires zero authentication — exposure alone is sufficient for compromise.
- Managed service providers or internal IT/monitoring teams running Skyeye as part of an asset-monitoring or ops stack, where a compromised instance could become a pivot point into the wider network.
- Environments that have not segmented monitoring tooling away from general-purpose or internet-facing network segments.
Potential Attack Chain
- Attacker identifies a network- or internet-reachable Skyeye instance; no login is required to reach the vulnerable endpoint.
- Attacker sends a crafted HTTP POST to
/post/TtsController/textToSpeechwith aformatvalue containing a single quote followed by an attacker-chosen PowerShell command. TtsServiceImplconcatenates the unsanitized value into a PowerShell command line and invokes it viaRuntime.getRuntime().exec().- PowerShell parses the broken string as two statements: the intended TTS formatting call, and the attacker's injected command.
- The injected command executes with the privileges of the Skyeye service account on the host.
- The attacker now has remote code execution, which can be chained into persistence (new scheduled tasks or local accounts), credential harvesting, lateral movement, or deployment of further malware/ransomware.
Mitigation
Immediate Actions
- Take internet-facing Skyeye instances offline, or restrict access to a VPN/trusted management network, until a fix is confirmed — the endpoint's lack of authentication means network reachability alone is enough to exploit it.
- Check whether an upstream fix has landed beyond commit
003549ae5615bd114ba5bb8ddf6a8e8ead97c321; no officially tagged patched release had been published at the time of writing — monitor the upstreamdromara/skyeyerepository for updates. - If the text-to-speech feature is not in active use, disable or block the
/post/TtsController/textToSpeechroute at the application layer or reverse proxy. - Review the privilege level of the Windows service account running Skyeye; run it with the minimum privileges necessary rather than an elevated or administrative identity.
Detection Opportunities
- Review web/application logs for POST requests to
/post/TtsController/textToSpeechwhere theformatfield contains single quotes, semicolons, or PowerShell keywords such asInvoke-Expression,IEX,Start-Process, or-EncodedCommand. - Alert on
powershell.exechild processes spawned by the Skyeye Java process with command-line content that does not match expected TTS parameters. - Watch for unusual outbound connections, newly created scheduled tasks, or new local accounts appearing on hosts running Skyeye shortly after an unauthenticated request to the TTS endpoint.
Defence-in-Depth
- Deploy a WAF or reverse proxy in front of Skyeye that blocks requests containing shell metacharacters (apostrophes, semicolons, backticks) in parameter values as a compensating control.
- Segment monitoring and operations tooling such as Skyeye onto a restricted management network rather than general-purpose or internet-facing segments.
- Treat the bundled xxl-job-admin component the same way — its
/jobinfo/addAndStartendpoint carries its own unauthenticated code-execution path (CVE-2026-107779) and should be remediated in the same change window.
Discovery & Disclosure
- Published: October 8, 2026 (NVD).
- Credit: Reported by security researcher "Ikram-4."
- CISA KEV status: Not currently listed in the CISA Known Exploited Vulnerabilities catalog as of this advisory's publish date. This page will be updated if that changes.
- PoC status: Public write-ups describe the vulnerable code path and the single-quote injection mechanism in detail, but no confirmed public exploit tool or weaponized PoC had been identified at the time of writing. Treat this as unconfirmed rather than as evidence of safety — reassess as new reporting emerges.
- Vendor response: The public GitHub issue tracking this finding and two related findings (
dromara/skyeye#29) showed no patch commit or substantive maintainer response at the time of writing.
References
- NVD — CVE-2026-107780
- GitHub Issue — dromara/skyeye#29
- Strix — CVE-2026-107780: skyeye OS Command Injection (CVSS 9.8)
Related, separately-tracked issues disclosed in the same batch: CVE-2026-107779 is a missing-authentication flaw in Skyeye's bundled xxl-job-admin component that allows unauthenticated job submission (GLUE_SHELL/GLUE_PYTHON/GLUE_POWERSHELL) via /jobinfo/addAndStart — a distinct root cause (CWE-306) from the string-concatenation bug described in this advisory. CVE-2026-107781 (CVSS 7.4) is an SSRF and missing-authorization issue in Skyeye's OnlyOffice save callback. Organizations running Skyeye should remediate all three in the same maintenance window.