<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Critical Unpatched RCE Vulnerability in Hugging Face LeRobot Robotics Platform]]></title><description><![CDATA[<p>Critical Unpatched RCE Vulnerability in Hugging Face LeRobot Robotics Platform</p><p>Hugging Face's LeRobot robotics platform contains a critical unpatched vulnerability (CVE-2026-25874) that allows unauthenticated remote code execution via unsafe pickle deserialization. Attackers can exploit exposed gRPC endpoints to take full control of robotics servers and connected hardware.</p><p>**If you're using Hugging Face LeRobot, make sure all robot devices and servers are isolated from the internet and accessible only from trusted networks. Until version 0.6.0 is released with a fix for CVE-2026-25874, run LeRobot as a non-root user inside restricted containers, and monitor for unusual processes or outbound traffic.**<br /><a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/advisory" rel="tag">#<span>advisory</span></a> <a href="https://infosec.exchange/tags/vulnerability" rel="tag">#<span>vulnerability</span></a><br /><a href="https://beyondmachines.net/event_details/critical-unpatched-rce-vulnerability-in-hugging-face-lerobot-robotics-platform-z-j-o-7-g/gD2P6Ple2L" rel="nofollow noopener"><span>https://</span><span>beyondmachines.net/event_detai</span><span>ls/critical-unpatched-rce-vulnerability-in-hugging-face-lerobot-robotics-platform-z-j-o-7-g/gD2P6Ple2L</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/63bbe77f-c512-4e15-9553-cffc2dbfbbdb/critical-unpatched-rce-vulnerability-in-hugging-face-lerobot-robotics-platform</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 02:30:18 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/63bbe77f-c512-4e15-9553-cffc2dbfbbdb.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 13:01:43 GMT</pubDate><ttl>60</ttl></channel></rss>