Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LeRobot Unsafe Deserialization Remote Code Execution via gRPC
Vulnerability Description
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payload through the SendPolicyInstructions, SendObservations, or GetActions gRPC calls.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
lerobot 代码问题漏洞
Vulnerability Description
lerobot是Hugging Face开源的一个机器人编程库。 LeRobot 0.5.1及之前版本存在代码问题漏洞,该漏洞源于异步推理管道中的不安全反序列化,其中pickle.loads()用于反序列化通过未经身份验证的gRPC通道接收的数据,允许未经身份验证的网络可达攻击者通过发送特制pickle有效载荷实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A