Critical Flaw in Hugging Face's Open-Source LeRobot Platform Could Enable Remote Code Execution
Hugging Face's open-source LeRobot platform allows developers to train, deploy and control AI robots, while its PolicyServer handles inference and control requests. CVE-2026-25874 affects a core service that can connect to physical devices. Exploitation could compromise AI system data and potentially jeopardize the operational safety of robots.
Disclosed in 2026, CVE-2026-25874 is classified as a critical vulnerability caused by unsafe deserialization in PolicyServer's data handling. An unauthenticated attacker can send a malicious payload through a gRPC call to remotely execute arbitrary code. No patch was available as of July 20, 2026, and users should restrict external connectivity to the service and strengthen access controls.
All Coverage
1 original reportsThe Backstory
The history behind this eventApril 29 Cybersecurity Briefing: Critical LiteLLM and LeRobot Flaws Emerge as AI Agent Deletes Data
LiteLLM is an agent gateway that integrates multiple large language models, while Hugging Face’s LeRobot provides tools for robotics AI development. A compromise of either platform could expose model credentials, servers and automated workflows. Giving AI agents database access also means a single error can rapidly escalate into an operational incident.
An April 29 cybersecurity advisory said attacks targeting a high-risk LiteLLM vulnerability began just a day and a half after its disclosure, while a critical flaw was also uncovered in the LeRobot platform. Separately, a startup using a Cursor/Anthropic AI agent had its entire production database and backups deleted within nine seconds. The organizations involved have not disclosed the amount of the losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.