Executive brief
Hugging Face LeRobot, an open-source robotics framework, contains a critical security flaw in its remote communication system. This system allows robots to offload complex calculations to a more powerful server. Because the software does not properly verify the data it receives over the network, an attacker can send malicious commands that take complete control of either the robot or the server. This could lead to unauthorized access to sensitive camera feeds, theft of proprietary AI models, or the execution of arbitrary code on connected hardware.
Technical details
LeRobot (up to version 0.5.1) contains an unsafe deserialization vulnerability (CWE-502) within its asynchronous inference pipeline. The 'PolicyServer' and 'RobotClient' components utilize Python's 'pickle.loads()' to process data received via gRPC calls, including 'SendPolicyInstructions', 'SendObservations', and 'GetActions'. These gRPC channels are unauthenticated and do not use TLS (configured via 'add_insecure_port'). An attacker can achieve arbitrary code execution by sending a crafted pickle payload; the execution occurs during deserialization, before any type validation (such as 'isinstance' checks) is performed. A patch is available in version 0.6.0 which refactors the communication protocol to avoid unsafe deserialization.
Affected products
- Hugging Face LeRobot <= 0.5.1
Timeline
- 2025-12: disclosed: Initial private report submitted via GitHub Security tab by independent researcher.
- 2026-01-07: other: Maintainer acknowledged the security risk in public issue tracker.
- 2026-04-22: other: Detailed technical write-up and PoC published by researcher.
- 2026-04-23: advisory: CVE-2026-25874 published.