THREAT OPS › Threat News › [GHSA] GHSA-m2pc-3q4q-w6jr (medium) — reachy_mini Allows Unrestricted Upload of File with Dangerous Type
[GHSA] GHSA-m2pc-3q4q-w6jr (medium) — reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-m2pc-3q4q-w6jr Severity: medium CVE: CVE-2026-55419
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
## Summary
The Reachy Mini daemon exposes the “/api/media/sounds/upload” endpoint without authentication and file validation mechanisms. An attacker can use this endpoint to upload malicious files into the file system that will propagate in future attacks.
## Compromise
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-55419cve
Original source: https://github.com/advisories/GHSA-m2pc-3q4q-w6jr