CVE-2026-25874
CVSS 9.8 CRITICAL: leRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where… EPSS 1.0% (60º percentile).
Vulnerabilità ed exploit
A single crafted pickle can compromise both sides of a LeRobot deployment. The bug is not just a server issue. It also reaches the robot client, so patching one component does not remove the attack surface if the other stays exposed.
CVE-2026-25874 affects Hugging Face LeRobot 0.4.3 and allows unauthenticated remote code execution through unsafe pickle deserialization over gRPC. The flaw sits in the async inference pipeline, where policy server and robot client components accept unauthenticated data without TLS.
That widens the blast radius across networked robots and controllers. An attacker who can reach the service can take over the host, steal secrets, move laterally, or disrupt physical operations, and the risk persists anywhere the platform is exposed on a network.
1 fonte · 28 apr
CVSS 9.8 CRITICAL: leRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where… EPSS 1.0% (60º percentile).
The Hacker News
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
CVE-2026-25874 (CVSS 9.3) in LeRobot 0.4.3 allows unauthenticated RCE via pickle over gRPC, risking AI systems and sensitive data.
originalePart of the PlainSec briefing for 2026-04-29
Every edition of this story: LeRobot Deserialization Flaw Can Take Over Robots and Controllers