Briefing

LeRobot Vulnerability CVE-2026-25874 Enables Remote Code Execution via Untrusted Deserialization

security
by [email protected] (The Hacker News) · CVE-2026-25874

Patch LeRobot to the latest version or apply the security advisory immediately.

What to do now

Patch LeRobot to the latest version or apply the security advisory immediately.

Summary

LeRobot, the open‑source robotics platform from Hugging Face with nearly 24,000 GitHub stars, is impacted by CVE-2026-25874, a remote code execution flaw caused by untrusted data deserialization. The vulnerability has a CVSS score of 9.3 and allows an attacker to execute arbitrary code on any system that deserializes untrusted input from the platform. The flaw can affect any component that processes external data, including robot controllers and APIs. Hugging Face has released a patch and issued a security advisory. Users should update LeRobot to the latest version immediately to mitigate the risk. The incident highlights the dangers of insecure deserialization in robotics software.

Key changes

  • CVE-2026-25874 in LeRobot platform causes untrusted data deserialization.
  • CVSS score 9.3, remote code execution possible.
  • LeRobot has nearly 24,000 GitHub stars.
  • Vulnerability affects any component that deserializes untrusted input.
  • Patch released; update recommended.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting