{"apiVersion":"1.0","identifier":"CVE-2026-55419","description":"Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The daemon binds to 0.0.0.0 by default and uses permissive CORS allow_origins=[-*-], allowing an unauthenticated network attacker to upload arbitrary file types that are written to /tmp/reachy_mini_sounds/<original_filename>. Malicious files can compromise stored-data integrity and can serve as a foothold when combined with other vulnerabilities. This issue is fixed in version 1.8.2.","publishedAt":"2026-08-25T18:17:55","lastModifiedAt":"2026-08-26T20:17:53","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55419","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","epssProbability":0.00339,"riskScore":0.55,"affectedProduct":"reachy-mini","affectedVersions":"<1.8.2","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-55419","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-55419","en":"https://www.redsauce.net/en/cves/CVE-2026-55419","fr":"https://www.redsauce.net/fr/cves/CVE-2026-55419","pt":"https://www.redsauce.net/pt/cves/CVE-2026-55419","de":"https://www.redsauce.net/de/cves/CVE-2026-55419","sk":"https://www.redsauce.net/sk/cves/CVE-2026-55419","el":"https://www.redsauce.net/el/cves/CVE-2026-55419"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-55419"}}