CVE-2026-25874: Hugging Face LeRobot Unauthenticated RCE via Pickle Deserialization
ID: 1c84e18e-bafb-5efc-8700-a2e1ea98aebe
STIX ID: report--1c84e18e-bafb-5efc-8700-a2e1ea98aebe
Feed Name: Resecurity
**Executive Summary:** LeRobot's async inference PolicyServer exposes gRPC handlers that unserialize attacker-controlled data with Python's pickle, allowing unauthenticated remote code execution (CVE-2026-25874). A working PoC demonstrating exploitation of SendPolicyInstructions() and SendObservations() was validated against LeRobot v0.4.3; recommended mitigations include removing pickle from network input, enabling TLS and authentication, restricting network access, and hardening the host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
