CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-25874

Critical · CVSS 9.8

LeRobot (huggingface/lerobot) — Unsafe deserialization (pickle.loads) RCE over unauthenticated gRPC

CVSS
9.8
nvd
EPSS
15.5%
96th pct
KEV
No
Class
oss containerizable
CWE-502

Description

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.

Search profile — drives PoC discovery

Symbols pickle.loadsSendPolicyInstructionsSendObservationsGetActionspolicy_serverrobot_clientasync inference pipelinegRPC
Keywords CVE-2026-25874LeRobot pickle deserialization RCElerobot grpc pickle exploitlerobot unsafe deserializationlerobot policy server exploithuggingface lerobot RCElerobot SendPolicyInstructionslerobot SendObservationslerobot GetActionsCWE-502 lerobotlerobot grpc unauthenticatedchocapikk lerobot
Versions: <= 0.5.1

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z