CVE-2026-55419 | pollen-robotics reachy_mini up to 1.8.1 media.py upload_sound unrestricted upload

SecurityVulns

A vulnerability labeled as critical has been found in pollen-robotics reachy_mini up to 1.8.1. The impacted element is the function upload_sound of the file src/reachy_mini/daemon/app/routers/media.py. The manipulation results in unrestricted upload.

This vulnerability is known as CVE-2026-55419. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More