Fetching latest headlines…
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
NORTH AMERICA
πŸ‡ΊπŸ‡Έ United Statesβ€’April 28, 2026

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

0 views0 likes0 comments
Originally published byThe Hacker News
Cybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face's open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which has been described as a case of untrusted data deserialization stemming from the use of the

Comments (0)

Sign in to join the discussion

Be the first to comment!