Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks
ID: 38285981-0687-5c7d-a72b-f94aaca1e64e
STIX ID: report--38285981-0687-5c7d-a72b-f94aaca1e64e
Feed Name: cybersecurityNews.com
**Executive summary:** A critical unauthenticated remote code execution vulnerability (CVE-2026-25874, CVSS 9.3) has been disclosed in LeRobot’s async inference module due to insecure use of Python pickle over unauthenticated gRPC channels; attackers can send malicious serialized payloads (e.g., via SendPolicyInstructions or SendObservations) to achieve immediate arbitrary code execution on inference hosts. The flaw affects LeRobot up to 0.5.1, risks full administrative compromise of GPU inference servers, model corruption, key exfiltration, and potential physical impacts on connected robots; a permanent fix replacing pickle with safetensors/JSON is planned for 0.6.0 and immediate mitigations include binding services to localhost, enforcing TLS/authentication, and network-level access restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
