CVE-2026-25874
Last modified
CVE-2026-25874 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.. EPSS estimates a 15.55% chance of exploitation in the next 30 days.
Description
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huggingface | Lerobot | <= 0.5.1 |
References
- https://chocapikk.com/posts/2026/lerobot-pickle-rce/Exploit, Mitigation, Third Party Advisory
- https://github.com/huggingface/lerobot/issues/3047Exploit, Issue Tracking, Third Party Advisory
- https://github.com/huggingface/lerobot/issues/3134Issue Tracking
- https://github.com/huggingface/lerobot/pull/3048Issue Tracking, Patch
- https://www.vulncheck.com/advisories/lerobot-unsafe-deserialization-remote-code-execution-via-grpcExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25874?
How severe is CVE-2026-25874?
How do I fix CVE-2026-25874?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25868MiniGal Nano version 0.3.5 and prior contain a reflected cro…6.1
- CVE-2026-25869MiniGal Nano versions 0.3.5 and prior contain a path travers…7.5
- CVE-2026-2587A critical Remote Code Execution (RCE) vulnerability was ide…9.6
- CVE-2026-25870DoraCMS version 3.1 and prior contains a server-side request…6.9
- CVE-2026-25872JUNG Smart Panel KNX firmware version L1.12.22 and prior con…6.9
- CVE-2026-25873OmniGen2-RL contains an unauthenticated remote code executio…9.8
- CVE-2026-25875PlaciPy is a placement management system designed for educat…9.8
- CVE-2026-25876PlaciPy is a placement management system designed for educat…9.1
- CVE-2026-25877Chartbrew is an open-source web application that can connect…6.5
- CVE-2026-25878FroshAdminer is the Adminer plugin for Shopware Platform. Pr…5.3
- CVE-2026-25879Langroid is a framework for building large-language-model-po…9.8
- CVE-2026-2588Crypt::NaCl::Sodium versions through 2.001 for Perl has an i…9.1
Are you affected by CVE-2026-25874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
