BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hugging Face LeRobot Flaw Allows Remote Code Execution

Critical flaw in Hugging Face's LeRobot allows unauthenticated remote code execution via unsafe deserialization.

  • A critical security flaw (CVE-2026-25874) has been disclosed in Hugging Face’s open-source robotics platform, LeRobot, allowing unauthenticated remote code execution.
  • The flaw stems from unsafe deserialization using pickle.loads() on data from unauthenticated gRPC channels in the policy server and robot client components.
  • The vulnerability is currently unpatched, with a fix planned for version 0.6.0, and is dangerous as AI inference systems often run with elevated privileges.

Cybersecurity researchers revealed in April 2026 that Hugging Face’s popular open-source robotics platform, LeRobot, harbors a severe security vulnerability. This flaw allows unauthenticated attackers to execute arbitrary code remotely on systems running the service.

- Advertisement -

The vulnerability, cataloged as CVE-2026-25874 with a CVSS score of 9.3, is a case of unsafe deserialization. According to a GitHub advisory, the problem exists in the async inference pipeline where pickle.loads() deserializes data from unauthenticated gRPC channels.

An attacker who can reach the PolicyServer network port can send a malicious serialized payload. Consequently, they can run arbitrary operating system commands on the host, as detailed in a report by Resecurity.

The exploitation risks are significant because these AI inference systems typically have high privileges. Therefore, a compromise could lead to theft of sensitive data like API keys, lateral network movement, or even physical safety risks.

Valentin Lobstein, a VulnCheck researcher who discovered and published details of the flaw, noted it was validated against LeRobot version 0.4.3. Meanwhile, the issue remains unpatched, with a fix planned for version 0.6.0.

- Advertisement -

The flaw was independently reported in December 2025 by another researcher. Steven Palma, the project’s tech lead, acknowledged the risk and stated, “that part of the codebase needs to be almost entirely refactored as its original implementation was more experimental.”

Palma further noted that security was not a strong focus as LeRobot was primarily a research tool. However, he emphasized that closer attention would be paid as adoption grows, saying, “Fortunately, being an open-source project, the community can also help by reporting and fixing vulnerabilities.”

The findings highlight the ongoing danger of using the unsafe pickle format for serialization. Lobstein pointed out the irony, as Hugging Face created the Safetensors format specifically because pickle is dangerous for ML data.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Aave Could Outrun Bitcoin, Gain 50x By 2030: Analyst

Bitcoin has fallen over 50% from its October all-time high as a major crypto...

U.S., Ukraine Uncover Russian Cyber Spy Campaign

The Security Service of Ukraine and FBI uncovered a long-running Russian cyber-espionage campaign targeting...

Nvidia’s $1,000 IPO Investment Now Worth Multi-Millions

A $1,000 investment in NVIDIA at its 1999 IPO, adjusted for splits, would be...

Ripple processed $16T but used almost no crypto

Ripple CEO criticized Strategy's leveraged funding model for hurting the wider crypto market.Brad Garlinghouse...

OpenAI Previews GPT-5.6 AI Trio to US Agencies

OpenAI released three limited-preview versions of GPT-5.6: the flagship Sol, balanced Terra, and fast/affordable...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading