OSV 1.4.0 · github-reviewed · 修改于 2026-08-26 01:38
发布时间
2026-08-26 01:38
GitHub 审查时间
2026-08-26 01:38
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-m2pc-3q4q-w6jr/GHSA-m2pc-3q4q-w6jr.json
The Reachy Mini daemon exposes the “/api/media/sounds/upload” endpoint without authentication and file validation mechanisms.
An attacker can use this endpoint to upload malicious files into the file system that will propagate in future attacks.
This issue is part of a full compromise chain allowing an unauthenticated user to gain root access on the Reachy’s operating system:
The root cause of the issue is at the handler located in “src/daemon/app/routers/media.py” file at the “upload_sound” method:
@router.post("/sounds/upload")
async def upload_sound(
file: UploadFile = File(...),
) -> dict[str, str]:
"""Upload a sound file to the daemon's temporary sound directory.
The file is saved to ``/tmp/reachy_mini_sounds/<original_filename>``.
If a file with the same name already exists it is overwritten.
Returns:
JSON with the absolute *path* of the saved file on the daemon.
"""
if not file.filename:
raise HTTPException(status_code=400, detail="Filename is required")
# Reject path traversal
filename = Path(file.filename).name
if not filename or filename in (".", ".."):
raise HTTPException(status_code=400, detail="Invalid filename")
os.makedirs(SOUNDS_TMP_DIR, exist_ok=True)
dest = os.path.join(SOUNDS_TMP_DIR, filename)
content = await file.read()
with open(dest, "wb") as f:
f.write(content)
return {"status": "ok", "path": dest}
This endpoint lacks multiple defence mechanisms:
Additionally, the daemon is bound to the 0.0.0.0 network interfaces (a.k.a. all network interfaces) by default along with permissive CORS ( allow_origins=[“*”] ) meaning the following API endpoint is exposed to every network interface the daemon is connected to.
.venv/bin/mjpython -m reachy_mini.daemon.app.main --sim --no-media
curl -X POST http://<daemon_domain>:<daemon_port>/api/media/sounds/upload \
-F "file=@/path/to/your/file.wav"
curl -X POST http://<daemon_domain>:<daemon_port>/api/media/sounds/upload \
-F "file=@/path/to/your/script.sh"
Due to this issue, an attacker can upload malicious files instead of the intended sounds files, harming the integrity of the stored data and allowing an attacker to propagate a foothold in cases another vulnerabilities would arise.
Perform the following check on the API endpoint:
The vulnerability was discovered by Natan Nehorai of the JFrog Vulnerability Research team.