HomeCVE Intelligence › CVE-2026-25874
CVSS 8.0 HIGH 🔴 ACTIVELY EXPLOITED Zero-Day Exploit

CVE-2026-25874: Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

Cybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face's open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote cod…

8.0CVSS Score
HIGHSeverity
NOCISA KEV
Zero-Day ExploitImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-25874
VendorThe Hacker News
Affected ProductThreat Intelligence
Vulnerability TypeZero-Day Exploit
CVSS Score8.0 (HIGH)
Actively Exploited✅ Yes
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via thehackernews)

🔬 Technical Analysis

Cybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face's open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which has been described as a case of untrusted data deserialization stemming from the use of the

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-25874 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence