Tag
pickle deserialization
Safeguard articles tagged "pickle deserialization" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Security News
CVE-2026-25874: Unauthenticated RCE in Hugging Face's LeRobot
A critical, unauthenticated remote code execution flaw in Hugging Face's LeRobot robotics library stems from pickle deserialization over an unencrypted gRPC channel — putting arbitrary code execution directly on a robotics control plane.
Sep 16, 20266 min read
Security News
nullifAI: How Two Malicious Models Slipped Past Hugging Face's Scanner
ReversingLabs found two Hugging Face models that hid a reverse-shell payload from Picklescan by compressing pickle files with 7z instead of ZIP. Here's how the trick worked and why pickle-format models remain a code-execution risk.
Sep 16, 20266 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.