Severity:
HIGH RISK
(7.3)
OS Command Injection (CWE-78) in node-sonos-http-api TTS Provider for macOS
CVE-2026-2629
Published:
Feb 17, 2026
Status:
Received
Summary
Affected Context
Exploit Preconditions
Why This Happens
Potential Impact
General Mitigation Guidance
How Teams Detect Issues Like This
Frequently Asked Questions
Source
NDV
Recent Vulnerabilities
CWE-306
(9.8)
Missing Authentication for Forgot-Password Email Change API (CWE-306)
Account Takeover / Loss of Account Control
February 17, 2026
CWE-74;CWE-89
(7.3)
SQL Injection via PGUID Parameter (CWE-89) in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0
Data Exposure and Manipulation via SQL Injection
February 17, 2026







