GHSA-6h3w-5484-rrpwMediumCVSS 6.3

mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool ...

Published
September 29, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.

🔗 References (5)