Huggingface Lerobot
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Huggingface Lerobot.
By the Year
In 2026 there have been 1 vulnerability in Huggingface Lerobot.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 0.00 |
It may take a day or so for new Lerobot vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Huggingface Lerobot Security Vulnerabilities
LeRobot 0.5.1 Unsafe Deserialization via gRPC (Arbitrary Code Exec)
CVE-2026-25874
- April 23, 2026
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.
Marshaling, Unmarshaling
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Huggingface Lerobot or by Huggingface? Click the Watch button to subscribe.