Chocapikk[verified]@Chocapikk_PoC
The post announces two high‑severity RCEs due to unsafe pickle deserialization in HuggingFace LeRobot and KTransformers, links to writeups that likely contain PoC, and notes a pending patch for KTransformers.
YogSotho[verified]@YogSoth0Disclosure
The tweet announces a critical unauthenticated RCE vulnerability in HuggingFace's LeRobot platform caused by insecure pickle deserialization, describing the technical issue but providing no PoC, exploit code, or evidence of active exploitation.
J.D. Salbego[verified]@JDSalbegoDisclosure
Researchers disclosed a critical RCE in Hugging Face's LeRobot platform (CVE‑2026‑25874) via unsafe deserialization, highlighting physical‑world safety risks, with no PoC or patch referenced.
Nicolas Krassas[verified]@DinosnPoC
CVE-2026-25874 is an unauthenticated Pickle deserialization RCE in Hugging Face LeRobot’s AsyncInference PolicyServer, with a PoC and likely exploit code detailed in the linked blog, but no evidence of active exploitation or a vendor patch provided.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The tweet discloses CVE-2026-25874, detailing unsafe gRPC-based deserialization in LeRobot that allows remote code execution; a patch (0.6.0) is expected.
The MLSecOps Hacker[verified]@MLSecOpsHackerDisclosure
The post informs that Hugging Face’s LeRobot still exposes `pickle.loads()` over an unauthenticated gRPC channel (CVE‑2026‑25874), but it offers no exploit, patch, or evidence of active exploitation.
Vivek | Cybersecurity[verified]@VivekIntelDisclosure
The post announces an unauthenticated remote code execution flaw in an AI system via malicious pickle handling over gRPC, outlining its potential server, robot, and lateral movement impacts.
Orizon[verified]@OrizonCyberGeneral
The post alerts to CVE-2026-25874, an unauthenticated remote code execution flaw in Hugging Face's LeRobot with a CVSS score of 9.3, and notes that no patch is currently available.