logo

CVE-2026-25874: Hugging Face LeRobot Unauthenticated RCE via Pickle Deserialization

ID: 1c84e18e-bafb-5efc-8700-a2e1ea98aebe

STIX ID: report--1c84e18e-bafb-5efc-8700-a2e1ea98aebe

Feed Name: Resecurity

Threat Score
90/100

Date Published: 2026-04-27

Date Updated: 2026-07-27

...
...

**Executive Summary:** LeRobot's async inference PolicyServer exposes gRPC handlers that unserialize attacker-controlled data with Python's pickle, allowing unauthenticated remote code execution (CVE-2026-25874). A working PoC demonstrating exploitation of SendPolicyInstructions() and SendObservations() was validated against LeRobot v0.4.3; recommended mitigations include removing pickle from network input, enabling TLS and authentication, restricting network access, and hardening the host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.