PT-2026-81446 · Unknown · Reachy Mini
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Reachy Mini versions prior to 1.8.2
Description
The Reachy Mini daemon exposes the '/api/media/sounds/upload' endpoint, implemented by the
upload sound() function, without authentication, file-extension checks, content validation, or size validation. By default, the daemon binds to 0.0.0.0 and uses permissive CORS (Cross-Origin Resource Sharing) settings, allowing an unauthenticated network attacker to upload arbitrary file types to the /tmp/reachy mini sounds/<original filename> directory. This can compromise stored-data integrity and serve as a foothold for further attacks, such as gaining root access when combined with other issues like Bluetooth authentication bypass and directory traversal.Recommendations
Update to version 1.8.2.
As a temporary workaround, restrict network access to the '/api/media/sounds/upload' endpoint to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Reachy Mini