Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

Source: The Hacker News  ·  Category: Security News — Technology


Hugging Face LeRobot (robotics platform) has unpatched RCE vulnerability (CVE-2026-25874, CVSS 9.3) via untrusted deserialization. If the firm uses or integrates LeRobot in any AI/ML pipeline, patch immediately or disable until fix is available.

→ Read the full article

Read more