Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55419— Reachy Mini: Unrestricted Upload of File with Dangerous Type

Quick assessment

Affected
pollen-robotics reachy_mini
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Reachy Mini 是用于控制 Reachy Mini 机器人的软件开发工具包(SDK)。在 1.8.2 版本之前,Reachy Mini 守护进程(daemon)的 端点(由 中的 方法实现)未进行身份验证,且缺少文件扩展名检查、内容验证和文件大小限制。该守护进程默认绑定到 ,并使用宽松的 CORS 配置 ,这使得未授权的网络攻击者能够上传任意类型的文件,这些文件会被写入 。恶意文件可能破坏存储数据的完整性,并可在与其他漏洞结合利用时提供攻击入口(立足点)。该问题已在 1.8.2 版本中修复。

CVSS 5.3 · Medium EPSS 0.34% · P26

Affected Version Matrix 1

VendorProduct Version RangeStatus
pollen-robotics reachy_mini < 1.8.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55419

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reachy Mini: Unrestricted Upload of File with Dangerous Type
Source: CVE Program / CVE List V5
Vulnerability Description
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The daemon binds to 0.0.0.0 by default and uses permissive CORS allow_origins=["*"], allowing an unauthenticated network attacker to upload arbitrary file types that are written to /tmp/reachy_mini_sounds/<original_filename>. Malicious files can compromise stored-data integrity and can serve as a foothold when combined with other vulnerabilities. This issue is fixed in version 1.8.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pollen-robotics reachy_mini < 1.8.2 -

II. Public POCs for CVE-2026-55419

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55419

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55419 (2)

Vendor Advisories for CVE-2026-55419 (1)

Vendor Pages for CVE-2026-55419 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55419

No comments yet


Leave a comment