UNKNOWN NVD
CVE-2026-79535
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied valu
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
References
- https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f61e48
- https://github.com/mbailey/voicemode/releases/tag/v8.10.2
- https://www.traceforce.ai/security-advisories/cve-2026-79535
This unknown severity vulnerability was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.