CVE-2026-79535

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the 'voicemode config set' CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.

https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f…
https://github.com/mbailey/voicemode/releases/tag/v8.10.2
https://www.traceforce.ai/security-advisories/cve-2026-79535