CVE-2026-76639 is an unauthenticated, network-adjacent remote code execution vulnerability in Unitree G1 EDU firmware through 1.5.2. The chat_go knowledge-upload API fails to validate an attacker-controlled identifier used in file-write path construction, permitting directory traversal and arbitrary file placement as root. The issue is chained with an unauthenticated WebRTC-to-DDS bridge or unauthenticated DDS communications and bashrunner behavior that rebuilds a script allowlist after restart and invokes allowlisted content through a shell without extension validation. An attacker can place a shell payload in a bashrunner-executable location, restart the service to incorporate it into the allowlist, and trigger root execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chaîne d’exécution de code à distance affectant le robot humanoïde Unitree G1. Une traversée de répertoires dans le service IA chat_go permet d’écrire un fichier contrôlé par l’attaquant dans le répertoire de contenu de bashrunner; après redémarrage, bashrunner ajoute ce fichier à sa whitelist et l’exécute via le shell. L’accès est possible via WebRTC avec une clé AES propre au robot ou via CycloneDDS Domain 0 sans authentification.
An unauthenticated, network-adjacent remote code execution vulnerability in Unitree G1 EDU firmware through version 1.5.2. Attackers can chain an exposed WebRTC-to-DDS bridge, a world-readable static AES-128 key, and path traversal in the chat_go knowledge upload API to plant and execute a payload as root via the bashrunner service.
An unauthenticated, network-adjacent remote-code-execution vulnerability in Unitree G1 EDU firmware through version 1.5.2. An attacker can chain an exposed WebRTC-to-DDS bridge, access to a world-readable static AES-128 key, and path traversal in the chat_go knowledge-upload API to restart bashrunner, place a malicious payload in its execution directory, and execute it as root.
An unauthenticated root remote-code-execution chain on Unitree G1 robots. A path traversal in chat_go's knowledge-upload API permits arbitrary root file writes; restarting bashrunner adds the written file to its import-time directory whitelist, after which bashrunner executes it with sh as root. The chain can be delivered through the authenticated WebRTC-to-DDS bridge after obtaining the device AES key, or directly over unauthenticated CycloneDDS Domain 0 where raw DDS publishing is possible.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.