Dromara Skyeye 通过提交 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 存在一个 OS 命令注入漏洞,该漏洞出现在未认证访问的 /post/TtsController/textToSpeech 端点中,具体是在 format 参数处。攻击者可以通过在 format 参数中注入单引号,从而突破 PowerShell 字符串限制,并在 Windows 系统上以 Skyeye 服务账户的身份执行命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107779 | 9.8 CRITICAL | Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE |
| CVE-2026-107781 | 7.4 HIGH | Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById |
No comments yet