Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Duhow
Duhow xiaoai-patch |
|
| Vendors & Products |
Duhow
Duhow xiaoai-patch |
Mon, 10 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home Assistant instance without validating the destination URL, enabling internal network scanning and access to internal services. | |
| Title | duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-10T13:17:02.096Z
Reserved: 2026-08-10T10:32:53.854Z
Link: CVE-2026-72581
Updated: 2026-08-10T13:16:57.876Z
Status : Received
Published: 2026-08-10T11:17:31.017
Modified: 2026-08-10T14:17:28.633
Link: CVE-2026-72581
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:23:47Z