PT-2026-102818 · Mbailey · Voicemode

·

CVE-2026-79535

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions mbailey VoiceMode versions prior to 8.10.2
Description OS Command Injection occurs when the update config MCP tool and the voicemode config set CLI write a caller-supplied value into the ~/.voicemode/voicemode.env file without shell-safe escaping. This allows an attacker to execute arbitrary operating system commands.
Recommendations Update mbailey VoiceMode to version 8.10.2 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79535

Affected Products

Voicemode