Skip to content
Critical RCE Vulnerability in Hugging Face LeRobot Exposes Systems to Attack

Critical RCE Vulnerability in Hugging Face LeRobot Exposes Systems to Attack

First seen 28 Apr 2026, 17:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 29, 2026 at 17:06 UTC
  • CVE-2026-25874 is a critical RCE vulnerability in Hugging Face's LeRobot framework.
  • The flaw allows unauthenticated attackers to execute arbitrary commands on servers.
  • LeRobot has over 21,500 stars on GitHub, indicating widespread use and risk.

A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-25874, has been identified in Hugging Face's LeRobot, an open-source robotics machine learning framework. This flaw, which has a CVSS severity score of 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers. With over 21,500 stars on GitHub, LeRobot's widespread use increases the risk of exploitation. The vulnerability was published on April 23, 2026, and remains unpatched as of April 28, 2026. Organizations using LeRobot are at significant risk of compromise if they do not take immediate action to secure their systems. Security professionals are urged to assess their environments for this vulnerability and implement mitigation strategies. The potential for mass exploitation is high given the framework's popularity in the machine learning community.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 134d ago How this analysis works

Timeline

2026-04-23
CVE-2026-25874 published
2026-04-28
Vulnerability remains unpatched and widely reported

More articles in this cluster (3)

Following this threat?

Track CVE-2026-25874 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed