Two Critical Root RCE Vulnerabilities in Unitree G1 EDU Humanoid Robots
Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) vulnerabilities in the Unitree G1 EDU humanoid robot, one via Bluetooth Low Energy (BLE) and another through a network-adjacent path. No confirmed firmware fixes have been released for CVE-2026-76639 and CVE-2026-76640, leaving users vulnerable to potential exploitation.
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC.
The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
*** END OF TRANSMISSION ***