Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot. The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, allow an attacker to achieve root-level access on the robot's Locomotion PC. One chain is exploitable over Bluetooth Low Energy (BLE), while the other uses a network-adjacent path through the chat_go and bashrunner components. Successful exploitation could let an attacker take full control of the robot, potentially causing physical harm. Patch information is not yet available.




















