Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Duhow
Duhow xiaoai-patch |
|
| Vendors & Products |
Duhow
Duhow xiaoai-patch |
Mon, 10 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system() without sanitization, enabling command injection via shell metacharacters. | |
| Title | duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-10T13:16:18.153Z
Reserved: 2026-08-10T10:32:53.854Z
Link: CVE-2026-72580
Updated: 2026-08-10T13:16:14.209Z
Status : Received
Published: 2026-08-10T11:17:30.897
Modified: 2026-08-10T14:17:28.510
Link: CVE-2026-72580
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:23:49Z