What is CVE-2026-72581?
CVE-2026-72581 is a server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch that allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs via the user-supplied 'url' POST parameter in the /auth endpoint. This can lead to unauthorized access to internal resources, and patching is required to mitigate the risk.
Azərbaycanca: CVE-2026-72581, duhow/xiaoai-patch proqramında server tərəfli sorğu saxtakarlığı (SSRF) zəifliyidir. Bu, uzaqdan hücum edənə Xiaomi ağıllı səs dinamikini aldadaraq daxili və ya xarici URL-lərə HTTP sorğuları göndərməyə imkan verir. İstifadəçi tərəfindən təqdim edilən 'url' POST parametri düzgün yoxlanılmadığı üçün təhlükəsizlik tədbirləri görülməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ1
How can an attacker exploit CVE-2026-72581 to trick a Xiaomi smart speaker?
An attacker can remotely trick the smart speaker into performing HTTP requests to arbitrary internal or external URLs by manipulating the user-supplied 'url' POST parameter in requests sent to the /auth endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.