CVE-2026-79535
N/A
N/A
Summary
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
References
- https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f61e48
- https://github.com/mbailey/voicemode/releases/tag/v8.10.2
- https://www.traceforce.ai/security-advisories/cve-2026-79535
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.