THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m2pc-3q4q-w6jr (medium) — reachy_mini Allows Unrestricted Upload of File with Dangerous Type

[GHSA] GHSA-m2pc-3q4q-w6jr (medium) — reachy_mini Allows Unrestricted Upload of File with Dangerous Type

medgithub_advisoriesPublished 2026-08-25

GHSA-m2pc-3q4q-w6jr Severity: medium CVE: CVE-2026-55419

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

## Summary

The Reachy Mini daemon exposes the “/api/media/sounds/upload” endpoint without authentication and file validation mechanisms. An attacker can use this endpoint to upload malicious files into the file system that will propagate in future attacks.

## Compromise

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m2pc-3q4q-w6jr