An authenticated Reachy Mini Bluetooth session can make the robot run an attacker-chosen script as root.
Pollen Robotics Reachy Mini, a small robot whose daemon exposes Bluetooth setup and command services on the robot host.
The CMD_ handler in the robot's Bluetooth command service joins attacker-controlled input into a script path and calls sudo on the result. Absolute paths and ../ traversal both escape the commands/ directory the design assumed, so anything already on the filesystem ending in .sh can be selected. Reaching it takes Bluetooth range and an authenticated command session.
Detail and 6 sources
The reason to watch this rather than file it is composition. JFrog names a separate media-sounds upload flaw as one way to get a .sh file onto the device, and describes a Bluetooth authentication bypass as the remaining step toward compromise with no credentials at all. Each piece is documented; the assembled version is what would matter.
The vendor advisory carries failing regression tests for both relative and absolute traversal payloads, and the public fix commit strips slashes and constrains command names to a basename character set before joining them under commands/.
A specialized robot is a small population, and that is the honest reason this sits here rather than higher.