Critical RCE Vulnerability in Hugging Face LeRobot Exposes Systems to Attack
ID: 8a304412-1e70-5e37-8dae-5ab2a9241f9e
STIX ID: report--8a304412-1e70-5e37-8dae-5ab2a9241f9e
Feed Name: ThreatCluster
Threat Score
**Critical RCE in Hugging Face LeRobot (CVE-2026-25874)** — A critical unauthenticated remote code execution vulnerability with a CVSS of 9.8 was disclosed in Hugging Face's open-source LeRobot framework on 2026-04-23 and reported unpatched as of 2026-04-28; the project's broad adoption (approximately 21,500 GitHub stars) raises the potential for mass exploitation and organizations are advised to assess and mitigate exposure immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
