CVE-2026-79535
Description
AI Translation Available
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the 'voicemode config set' CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f…
https://github.com/mbailey/voicemode/releases/tag/v8.10.2
https://www.traceforce.ai/security-advisories/cve-2026-79535