Vulnerability  ·  2026-09-30

VoiceMode MCP OS command injection in update_config tool (unsafe env-file writing)

VulnerabilityMedium impactGlobalCVE-2026-79535
NVD published CVE-2026-79535 on 2026-09-29. VoiceMode's config update path writes user-controlled content into voicemode.env with no shell-safe escaping, enabling OS command injection; fixed in v8.10.2 (commit c1cef85).
VoiceMode is a voice-agent MCP tool; the config-write path is the agent-tool surface through which a manipulated config value can escalate to OS command execution on the machine running the voice agent, though the package has a narrow (single-author) deployment footprint.
The update_config MCP tool (and the CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping; crafted values inject shell syntax when the env file is later sourced/executed by the voice agent.
mbailey VoiceMode <= 8.10.1 (update_config MCP tool and 'voicemode config set' CLI)
Upgrade to VoiceMode 8.10.2+ (commit c1cef85333fca497c46a11950911d10123f61e48); sanitize config values before writing to the env file.
NVD CVE-2026-79535VoiceMode fix commit
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →