Junglewise Threat Intelligence

CVE-2026-72581: xiaoai-patch SSRF in authentication endpoint

CVE-2026-72581 · Severity: high · CVSS 8.6 · Published 2026-08-10

Executive brief

xiaoai-patch is a patching utility for Xiaomi smart speakers that extends their functionality. A flaw in the authentication endpoint allows an attacker to trick the speaker into making HTTP requests to internal network addresses or external systems, potentially exposing sensitive services or enabling network reconnaissance.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the /auth endpoint within api/main.py. The endpoint accepts a user-supplied url POST parameter and uses it to redirect to a Home Assistant instance without validating the destination URL. An attacker can send a crafted request to make the smart speaker perform HTTP requests to arbitrary internal or external URLs, enabling internal network scanning, service enumeration, and access to internal resources. The attack is network-accessible and requires no authentication or user interaction.

Affected products

  • duhow xiaoai-patch through commit fb07049

Timeline

  • 2026-08-10: disclosed

References