PT-2026-53102 · Unknown · Xiaozhi-Esp32

·

CVE-2026-13489

·

Published

2026-06-28

·

Updated

2026-06-29

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions xiaozhi-esp32 versions prior to 2.2.7
Description A weakness in the MCP Response Handler component allows for improper synchronization. This issue occurs within the ParseMessage() function located in the main/mcp server.cc file. Remote exploitation is possible, although the attack complexity is rated as high and exploitation is considered difficult.
Recommendations Update xiaozhi-esp32 to a version newer than 2.2.6. As a temporary mitigation, restrict access to the ParseMessage() function within the MCP Response Handler component.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13489

Affected Products

Xiaozhi-Esp32