Two AI infrastructure projects, KTransformers and LeRobot, were found vulnerable to unauthenticated remote code execution caused by unsafe deserialization of attacker-controlled data with pickle.loads(). KTransformers through version 0.5.3 is affected in its balance_serve backend mode, where the scheduler RPC server binds a ZeroMQ ROUTER socket to all interfaces without authentication and processes untrusted messages, allowing an attacker to send a crafted pickle payload and execute arbitrary code with the privileges of the ktransformers process. The issue was tracked as CVE-2026-26210, mapped to CWE-502, and assigned a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
LeRobot through version 0.5.1 was similarly exposed through its async inference pipeline, where policy server and robot client components deserialize data received over unauthenticated gRPC channels without TLS. A network-reachable attacker can trigger code execution on either side by sending crafted payloads through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls. That flaw, tracked as CVE-2026-25874, also carries a CWE-502 classification and a CVSS v4.0 rating reflecting low-complexity network exploitation with no privileges or user interaction and high impact to confidentiality, integrity, and availability. Public references for both issues include technical write-ups, GitHub remediation activity, and VulnCheck advisories.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
A remote code execution flaw in KTransformers was disclosed affecting versions through 0.5.3. In balance_serve backend mode, the scheduler RPC server binds a ZeroMQ ROUTER socket to all interfaces without authentication and deserializes attacker-controlled messages with pickle.loads(), enabling arbitrary code execution.
VulnCheck disclosure records show CVE-2026-25874 was received and modified on the same day to clarify that affected versions include LeRobot through 0.5.1. References added included GitHub issues, a pull request, a VulnCheck advisory, and a technical blog post.
A remote code execution vulnerability in LeRobot was documented affecting versions through 0.5.1. The flaw stems from unauthenticated gRPC communications in the async inference pipeline where pickle.loads() deserializes untrusted data in policy server and robot client components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.