logo

Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks

ID: 38285981-0687-5c7d-a72b-f94aaca1e64e

STIX ID: report--38285981-0687-5c7d-a72b-f94aaca1e64e

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Abinaya

...
...

**Executive summary:** A critical unauthenticated remote code execution vulnerability (CVE-2026-25874, CVSS 9.3) has been disclosed in LeRobot’s async inference module due to insecure use of Python pickle over unauthenticated gRPC channels; attackers can send malicious serialized payloads (e.g., via SendPolicyInstructions or SendObservations) to achieve immediate arbitrary code execution on inference hosts. The flaw affects LeRobot up to 0.5.1, risks full administrative compromise of GPU inference servers, model corruption, key exfiltration, and potential physical impacts on connected robots; a permanent fix replacing pickle with safetensors/JSON is planned for 0.6.0 and immediate mitigations include binding services to localhost, enforcing TLS/authentication, and network-level access restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.