
New writeups: CVE-2026-25874 - HuggingFace LeRobot (21.5k stars) - Unauthenticated RCE via pickle deserialization in gRPC PolicyServer. CVSS 9.3. https://chocapikk.com/posts/2026/lerobot-pickle-rce/ CVE-2026-26210 - KTransformers (16.5k stars) - Unauthenticated RCE via pickle deserialization in ZMQ scheduler. CVSS 9.8. Fix PR submitted. https://chocapikk.com/posts/2026/ktransformers-pickle-rce/ As always, thanks to @VulnCheckAI for the CVE coordination.
Post summary
New writeups reveal that CVE-2026-25874 and CVE-2026-26210 involve unauthenticated RCE via pickle deserialization with high CVSS scores, and patches are underway.

