What happened
NVD published CVE-2026-79535 on 2026-09-29. VoiceMode's config update path writes user-controlled content into voicemode.env with no shell-safe escaping, enabling OS command injection; fixed in v8.10.2 (commit c1cef85).
Why it matters
VoiceMode is a voice-agent MCP tool; the config-write path is the agent-tool surface through which a manipulated config value can escalate to OS command execution on the machine running the voice agent, though the package has a narrow (single-author) deployment footprint.
Attack vector
The update_config MCP tool (and the CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping; crafted values inject shell syntax when the env file is later sourced/executed by the voice agent.
Affected systems
mbailey VoiceMode <= 8.10.1 (update_config MCP tool and 'voicemode config set' CLI)
Mitigation
Upgrade to VoiceMode 8.10.2+ (commit c1cef85333fca497c46a11950911d10123f61e48); sanitize config values before writing to the env file.