CVE-2026-25874Disclosure(huggingface / lerobot)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch huggingface lerobot systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lerobot

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 45 mentions across 17 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 43 signals
  • Disclosure: 27 classified signals
  • General: 6 classified signals
  • Peaked 15d ago at 11 mentions (2026-04-28); latest day: 1
  • 45 total mentions across 17 days

Affected systems

Products
lerobot

Deep dive

Activity timeline45 mentions / 17d
036811Mentions · 2026-04-23: 2Mentions · 2026-04-28: 11Mentions · 2026-04-29: 7Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Mentions · 2026-05-03: 4Mentions · 2026-05-07: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-17: 1Mentions · 2026-05-25: 4Mentions · 2026-05-26: 3Mentions · 2026-06-28: 1Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-17: 3Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-30: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-06-30: 1Exploit Tool / Code · 2026-06-29: 1Exploit Tool / Code · 2026-07-17: 2Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-07-17: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-04-29: 2Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-04-23: 2Technical Details · 2026-04-28: 11Technical Details · 2026-04-29: 7Technical Details · 2026-04-30: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-03: 3Technical Details · 2026-05-07: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-25: 4Technical Details · 2026-05-26: 3Technical Details · 2026-06-28: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-17: 3Technical Details · 2026-09-02: 104-2304-2804-2904-3005-0105-0305-0705-0905-1005-1705-2505-2606-2806-2906-3007-1709-02
Signal classification6 categories
Disclosure
2760.0%
General
613.3%
PoC
48.9%
Active Exploitation
48.9%
Patch
24.4%
Exploit
24.4%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-04-232
Disclosure1PoC1
2026-04-2811
Disclosure10General1
2026-04-297
Active Exploitation1Disclosure6
2026-04-302
Disclosure1General1
2026-05-011
Active Exploitation1
2026-05-034
Disclosure1General3
2026-05-071
Disclosure1
2026-05-091
Patch1
2026-05-101
General1
2026-05-171
PoC1
2026-05-254
Active Exploitation1Disclosure2PoC1
2026-05-263
Disclosure2Patch1
2026-06-281
Disclosure1
2026-06-291
PoC1
2026-06-301
Disclosure1
2026-07-173
Active Exploitation1Exploit2
2026-09-021
Disclosure1
Full discourse20 posts
  • Chocapikk@Chocapikk_
    PoC

    New writeups: CVE-2026-25874 - HuggingFace LeRobot (21.5k stars) - Unauthenticated RCE via pickle deserialization in gRPC PolicyServer. CVSS 9.3. https://chocapikk.com/posts/2026/lerobot-pickle-rce/ CVE-2026-26210 - KTransformers (16.5k stars) - Unauthenticated RCE via pickle deserialization in ZMQ scheduler. CVSS 9.8. Fix PR submitted. https://chocapikk.com/posts/2026/ktransformers-pickle-rce/ As always, thanks to @VulnCheckAI for the CVE coordination.

    Post summary

    The post announces two high‑severity RCEs due to unsafe pickle deserialization in HuggingFace LeRobot and KTransformers, links to writeups that likely contain PoC, and notes a pending patch for KTransformers.

    214146194.5K
    4.0K followersView on X
  • YogSotho@YogSoth0
    Disclosure

    #LeRobot Multi-Exploit Kit Overview Weaponized #exploit kit for #CVE-2026-25874 — Critical unauthenticated #RCE via insecure pickle deserialization in #HuggingFace's LeRobot robotics platform. #Vulnerability LeRobot's gRPC services use `pickle.load()` / `pickle.loads()` to deserialize data received over unauthenticated, TLS-less gRPC channels. An attacker can send a crafted malicious serialized #Python object that executes arbitrary code on the server when deserialized. #0days #security #cybersecurity #hacking #infosec #antisec @huggingface @LeRobotHF

    Post summary

    The tweet announces a critical unauthenticated RCE vulnerability in HuggingFace's LeRobot platform caused by insecure pickle deserialization, describing the technical issue but providing no PoC, exploit code, or evidence of active exploitation.

    2201941.2K
    1.9K followersView on X
  • J.D. Salbego@JDSalbego
    Disclosure

    Security researchers found a critical RCE vulnerability in Hugging Face's open-source robotics platform LeRobot. CVE-2026-25874. Unauthenticated remote code execution through unsafe deserialization in the inference pipeline. AI security isn't just about chatbots anymore. It's about the machines AI controls in the physical world. When an agent can move a robot arm, a code execution vulnerability isn't a data breach. It's a safety hazard.

    Post summary

    Researchers disclosed a critical RCE in Hugging Face's LeRobot platform (CVE‑2026‑25874) via unsafe deserialization, highlighting physical‑world safety risks, with no PoC or patch referenced.

    30031155
    23.4K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-25874: Hugging Face LeRobot – Unauthenticated Pickle RCE in the AsyncInference PolicyServer https://blog.securelayer7.net/cve-2026-25874-lerobot-pickle-deserialization-rce/

    Post summary

    CVE-2026-25874 is an unauthenticated Pickle deserialization RCE in Hugging Face LeRobot’s AsyncInference PolicyServer, with a PoC and likely exploit code detailed in the linked blog, but no evidence of active exploitation or a vendor patch provided.

    020402.3K
    160.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - LeRobot unsafe deserialization via gRPC leads to RCE (CVE-2026-25874) LeRobot uses pickle.loads() on data received over unauthenticated, non-TLS gRPC channels in its async inference pipeline. An attacker can send crafted payloads via RPC calls (e.g. SendPolicyInstructions, GetActions) to achieve remote code execution on server or client. 👉 Affected: <= 0.5.1 | Fix expected: 0.6.0

    Post summary

    The tweet discloses CVE-2026-25874, detailing unsafe gRPC-based deserialization in LeRobot that allows remote code execution; a patch (0.6.0) is expected.

    1004090
    237 followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    CVE-2026-25874: Hugging Face LeRobot – Unauthenticated Pickle RCE in the AsyncInference PolicyServer: https://blog.securelayer7.net/cve-2026-25874-lerobot-pickle-deserialization-rce/ #cybersecurity #informationsecurity #rce #cve #vulnerability #exploitation

    Post summary

    A new unauthenticated pickle deserialization Remote Code Execution vulnerability (CVE‑2026‑25874) was disclosed for Hugging Face’s LeRobot AsyncInference PolicyServer, with a blog post providing further details.

    00030465
    2.4K followersView on X
  • The MLSecOps Hacker@MLSecOpsHacker
    Disclosure

    /2 In 2026 Hugging Face’s own LeRobot still exposed `pickle.loads()` over an unauthenticated gRPC channel (CVE-2026-25874). New attack pattern: safe format, unsafe usage. The container is secure, but the pipeline, the converter, and the inference service are not.

    Post summary

    The post informs that Hugging Face’s LeRobot still exposes `pickle.loads()` over an unauthenticated gRPC channel (CVE‑2026‑25874), but it offers no exploit, patch, or evidence of active exploitation.

    1001056
    10 followersView on X
  • CyAsha@cyashadotcom
    Disclosure

    CVE-2026-25874: LeRobot RCE Vulnerability Raises Major Security Concerns #cybersecurity #cyashadotcom #Eternal https://www.cyasha.com/cve-2026-25874-lerobot-rce-vulnerability/

    Post summary

    The text announces a new remote code execution vulnerability (CVE-2026-25874) without providing detection/mitigation or exploit details.

    00101756
    8 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2026-25874 → unauthenticated RCE Attack: pickle.loads() on untrusted gRPC input Impact: • server compromise • robot control • lateral movement 👉 This is AppSec 101 failure in an AI system https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html

    Post summary

    The post announces an unauthenticated remote code execution flaw in an AI system via malicious pickle handling over gRPC, outlining its potential server, robot, and lateral movement impacts.

    10010346
    8.0K followersView on X
  • Orizon@OrizonCyber
    General

    Hugging Face's LeRobot: 24k GitHub stars, CVE-2026-25874 (CVSS 9.3), unauthenticated RCE, no patch. Your robot vacuum just became someone's backdoor 💀 #infosec #CVE

    Post summary

    The post alerts to CVE-2026-25874, an unauthenticated remote code execution flaw in Hugging Face's LeRobot with a CVSS score of 9.3, and notes that no patch is currently available.

    2000053
    25 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    Source: X search for vulnerability critical 2026 Posted: 2026-06-28T20:37:35.000Z Likes: 10 #LeRobot Multi-Exploit Kit Overview Weaponized #exploit kit for #CVE-2026-25874 — Critical unauthenticated #RCE via insecure pickle deserialization in #HuggingFace's LeRobot…

    Post summary

    The post announces a weaponized exploit kit targeting CVE‑2026‑25874, noting its critical unauthenticated RCE via insecure pickle deserialization in HuggingFace's LeRobot.

    1000057
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Weaponized #exploit kit for #CVE-2026-25874 — Critical unauthenticated #RCE via insecure pickle deserialization in #HuggingFace's LeRobot robotics platform.

    Post summary

    The post warns that CVE-2026-25874 has been weaponized in an exploit kit targeting HuggingFace’s LeRobot platform, enabling critical unauthenticated remote code execution via insecure pickle deserialization. No mitigation or PoC details are provided.

    1000056
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-25874: #LeRobot Multi-Exploit Kit Overview Weaponized #exploit kit for #CVE-2026-25874 — Critical unauthenticated #RCE via insecure pickle deserialization in #HuggingFace's LeRobot robotics platform. #Vulnerability LeRobot's gRPC services use pickle.load() /…

    Post summary

    An exploit kit targeting CVE-2026-25874 is announced, exploiting a critical unauthenticated RCE through insecure pickle deserialization, yet no patch details or active exploitation reports are provided.

    1000061
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Hugging Face's LeRobot 0.4.3 (and earlier) contains an unauthenticated remote code execution vulnerability (CVE-2026-25874, CVSS 9.8) via untrusted Python pickle deserialization over gRPC. No patch exists. Any exposed LeRobot deployment is a backdoor.

    Post summary

    Hugging Face's LeRobot 0.4.3 contains a severe unauthenticated RCE vulnerability (CVE-2026-25874) via pickle deserialization over gRPC, with no patch available; any exposed deployment is effectively a backdoor.

    1000039
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-25874 · 0.4.3 → 9.8 LeRobot's Pickle Trap: Hugging Face's 21,500-Star Framework Bleeds Unauthenticated RCE

    Post summary

    CVE-2026-25874 is a critical unauthenticated remote code execution flaw in Hugging Face’s 21,500‑star framework (v0.4.3) with a CVSS score of 9.8.

    1000035
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    LeRobot's Pickle Trap: Hugging Face's 21,500-Star Framework Bleeds Unauthenticated RCE Hugging Face's LeRobot 0.4.3 and earlier contains an unauthenticated remote code execution vulnerability CVE-2026-25874, CVSS 9.8 via untrusted Python pickle deserialization over gRPC.

    Post summary

    The message announces a high‑severity unauthenticated RCE in Hugging Face’s LeRobot (v0.4.3 and earlier) via pickle deserialization over gRPC, providing the CVE ID and CVSS score.

    1000034
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Sources http://Socket.dev: CanisterWorm targets Namastex AI packages StepSecurity: pgserve malicious versions (April 21) Palo Alto Networks: Bitwarden CLI supply chain attack GBHackers: Hugging Face LeRobot CVE-2026-25874 Chocapikk: LeRobot pickle RCE technical analysis

    Post summary

    The brief references several recent incidents—CanisterWorm targeting Namastex AI packages, a Bitwarden CLI supply chain attack, and a CVE‑2026‑25874 vulnerability in LeRobot—indicating active exploitation and the availability of technical details.

    1000072
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    On April 28, 2026, security researcher Valentin Lobstein published exploitation details for CVE-2026-25874, a critical insecure deserialization flaw in Hugging Face's LeRobot. The vulnerability exists in the asynchronous inference pipeline—specifically the PolicyServer…

    Post summary

    Valentin Lobstein released exploitation details for CVE-2026-25874, a critical insecure deserialization flaw in Hugging Face's LeRobot, indicating a proof‑of‑concept exists but no evidence of active attacks or patching has been disclosed.

    1000052
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-25874 (CVSS 9.3) in Hugging Face's LeRobot lets unauthenticated attackers execute arbitrary code on inference servers via malicious pickle payloads over unencrypted gRPC. The vulnerability exists in a production-grade robotics framework that's been deployed with…

    Post summary

    A new CVE-2026-25874 in Hugging Face's LeRobot permits unauthenticated remote code execution via malicious pickle payloads over unencrypted gRPC on inference servers.

    1000041
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    25874 CVSS — The Irony That Kills: Hugging Face LeRobot's Pickle RCE Shows Why AI Infrastructure Can't Trust Open Source. CVE-2026-25874 CVSS 9.3 in Hugging Face's LeRobot lets unauthenticated attackers execute arbitrary code on inference servers via malicious pickle…

    Post summary

    A newly disclosed severe remote code execution vulnerability (CVSS 9.3) in Hugging Face LeRobot allows attackers to execute arbitrary code on inference servers via malicious pickle files.

    1000046
    227 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphuggingfacelerobot-python-

Explore more