LeRobot Vulnerability CVE-2026-25874 Enables Remote Code Execution via Untrusted Deserialization
Patch LeRobot to the latest version or apply the security advisory immediately.
Patch LeRobot to the latest version or apply the security advisory immediately.
Summary
LeRobot, the open‑source robotics platform from Hugging Face with nearly 24,000 GitHub stars, is impacted by CVE-2026-25874, a remote code execution flaw caused by untrusted data deserialization. The vulnerability has a CVSS score of 9.3 and allows an attacker to execute arbitrary code on any system that deserializes untrusted input from the platform. The flaw can affect any component that processes external data, including robot controllers and APIs. Hugging Face has released a patch and issued a security advisory. Users should update LeRobot to the latest version immediately to mitigate the risk. The incident highlights the dangers of insecure deserialization in robotics software.
Key changes
- CVE-2026-25874 in LeRobot platform causes untrusted data deserialization.
- CVSS score 9.3, remote code execution possible.
- LeRobot has nearly 24,000 GitHub stars.
- Vulnerability affects any component that deserializes untrusted input.
- Patch released; update recommended.