Owners of the Unitree G1 EDU humanoid robot face two separate paths to full compromise, both ending in root access on the machine’s Locomotion PC. Researcher Olivier Laflamme disclosed the chains on August 27, tracking them as CVE-2026-76639 and CVE-2026-76640.
The first chain is network-adjacent, reaching bashrunner through a path-traversal condition in chat_go. Execution through bashrunner resolves to root on the Locomotion PC. The second starts at Bluetooth proximity: the initial write path accepts the bootstrap interaction without Bluetooth pairing, though the bootstrap material stays protected and later Wi-Fi provisioning steps still require the app’s authenticated BLE state.
Unitree has already closed part of the gap. The researcher found the cloud would hand over key-recovery material to any valid Unitree account, with no proof of robot ownership required, and the company fixed that check in July 2026. A cloud-assisted attack today needs an account bound to the target G1, or the relevant key material already in hand, per the August 27 write-up.
Remediation remains the sticking point. A confirmed patched build has yet to appear in any Unitree documentation the researcher could reach, leaving owners without a clear upgrade target for either vulnerability.
