PT-2026-81446 · Unknown · Reachy Mini

·

CVE-2026-55419

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Reachy Mini versions prior to 1.8.2
Description The Reachy Mini daemon exposes the '/api/media/sounds/upload' endpoint, implemented by the upload sound() function, without authentication, file-extension checks, content validation, or size validation. By default, the daemon binds to 0.0.0.0 and uses permissive CORS (Cross-Origin Resource Sharing) settings, allowing an unauthenticated network attacker to upload arbitrary file types to the /tmp/reachy mini sounds/<original filename> directory. This can compromise stored-data integrity and serve as a foothold for further attacks, such as gaining root access when combined with other issues like Bluetooth authentication bypass and directory traversal.
Recommendations Update to version 1.8.2. As a temporary workaround, restrict network access to the '/api/media/sounds/upload' endpoint to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55419
GHSA-M2PC-3Q4Q-W6JR
PYSEC-2026-3916

Affected Products

Reachy Mini