Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
CVE-2026-25874 (CVSS 9.3) in LeRobot 0.4.3 allows unauthenticated RCE via pickle over gRPC, risking AI systems and sensitive data.
Advertisement
More like this
Researchers uncover new DarkSword spyware variant affecting unpatched iPhones
9 to 5 Mac
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
The Hacker News
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The Hacker News