
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A major security flaw (CVE-2026-25874) in Hugging Face's LeRobot AI platform allows unauthenticated attackers to execute arbitrary code via the PolicyServer component, risking system compromise, data theft, and physical safety. No patch is available yet, prompting urgent mitigation measures.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (LeRobot AI inference platform) and a critical security vulnerability that allows arbitrary code execution, which can lead to significant harms including system compromise, data theft, disruption of AI operations, and physical safety risks. The vulnerability is directly related to the AI system's development and use, and the harm is either occurring or highly likely if exploited. This meets the criteria for an AI Incident as the AI system's malfunction has directly led or could lead to significant harm.[AI generated]