Critical deserialization flaws were disclosed in multiple AI and robotics components, allowing attackers to execute arbitrary code by sending crafted pickle payloads to exposed services. In Hugging Face’s LeRobot 0.4.3, CVE-2026-25874 affects the async inference PolicyServer, where the SendPolicyInstructions and SendObservations gRPC handlers call pickle.loads() on attacker-controlled bytes before validation. The service is exposed over an insecure gRPC port with no TLS or authentication, making network-accessible deployments vulnerable to unauthenticated remote code execution; the issue was rated CVSS 9.8 and no fix was available at disclosure. A separate flaw, CVE-2026-26210, was reported in ktransformers’ legacy balance_serve backend, where a ZeroMQ ROUTER socket bound on all interfaces forwards untrusted messages to worker threads that also invoke pickle.loads() without authentication, enabling unauthenticated remote code execution and prompting a fix PR.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
A new report said CVE-2026-25874 in Hugging Face LeRobot remained unpatched as of 2026-04-28, but a fix was planned for release in version 0.6.0. The flaw affects LeRobot 0.4.3's PolicyServer and can enable unauthenticated remote code execution via unsafe pickle deserialization over gRPC.
The LeRobot report states that CVE-2026-25874 was published on 2026-04-23. At that time, the report said no vendor fix had yet been issued.
A pull request to fix the ktransformers balance_serve pickle deserialization issue was submitted. The report indicates this occurred after disclosure of CVE-2026-26210.
A public report disclosed CVE-2026-26210 as a critical CVSS 9.8 vulnerability in ktransformers' legacy ZMQ scheduler, warning that attackers could identify the dynamic port from logs or scanning and exploit documented host-network Docker deployments. The report recommended replacing pickle, restricting network binding, and adding authentication.
A public report detailed CVE-2026-25874, assigning the LeRobot flaw a CVSS 9.8 score and demonstrating successful code execution against a stock installation using malicious pickle payloads sent through both vulnerable gRPC methods. The report noted the service was exposed over insecure gRPC with no TLS or authentication.
A critical remote code execution flaw was disclosed in kvcache-ai/ktransformers' legacy balance_serve backend, where a ZeroMQ ROUTER socket exposed on all interfaces forwards untrusted messages to worker threads that call pickle.loads() without authentication or validation. The issue affects deployments using --backend_type balance_serve, while the newer SGLang-based deployment is not affected.
The LeRobot report states that disclosure attempts were made in late 2025 and early 2026 before public publication. No fix had been issued at the time of the report.
Hugging Face's LeRobot 0.4.3 async inference PolicyServer was identified as vulnerable because two gRPC handlers in policy_server.py call pickle.loads() on attacker-controlled bytes before type validation. A network-accessible deployment could allow unauthenticated remote code execution through SendPolicyInstructions and SendObservations.
Microsoft's TensorWatch 0.9.1 opens a local ZMQ REP socket on 127.0.0.1:41459 when tw.Watcher() is called and deserializes incoming messages with pickle.loads() before validation, enabling local code execution by another user on the same machine. The issue is particularly relevant on shared systems and host-networked containers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceresecurity.com
Open sourcechocapikk.com
Open sourcechocapikk.com
Open sourcechocapikk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.