Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
Source: The Hacker News · Category: Security News — Technology
Hugging Face LeRobot (robotics platform) has unpatched RCE vulnerability (CVE-2026-25874, CVSS 9.3) via untrusted deserialization. If the firm uses or integrates LeRobot in any AI/ML pipeline, patch immediately or disable until fix is available.