Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
- Posted on April 28, 2026
- By The Hacker News
- 0 Views
- 1 min read
Hugging Face LeRobot 0.4.3 contains a critical vulnerability (CVE-2026-25874) with a CVSS score of 9.3 that enables remote code execution without authentication. The flaw exploits insecure pickle deserialization over gRPC protocols, creating significant security risks for AI systems and machine learning infrastructure. Organizations using affected versions face potential data breaches and unauthorized system compromise, requiring immediate patching to prevent exploitation.
Summary auto-generated by AI from the original publisher's content. Editorial standards.