Executive brief
Reachy Mini is a small robot that runs a daemon with an HTTP management API. An unauthenticated endpoint allows installation of arbitrary Python packages from Hugging Face Spaces without any credential check. On wireless models that expose the daemon to the local network, any nearby attacker can install and execute malicious code on the robot, leading to full device compromise and potential lateral movement into home or office networks.
Technical details
The POST /apps/install endpoint in the daemon lacks authentication and accepts a Hugging Face Space name, downloading and installing it as a Python package via uv or pip. Package installation triggers arbitrary build and setup code execution with the daemon's privileges. The daemon binds to 0.0.0.0 (all interfaces) on wireless models, making it reachable from any host on the same LAN; prior CORS restrictions do not protect against direct HTTP requests from network peers.
Affected products
- Pollen Robotics Reachy Mini before 1.8.3 or unpatched wireless models
Timeline
- 2026-09-23: disclosed: CVE-2026-96455 published