ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
EMBODIED AI SECURITY · INCIDENT INDEX · PV-013

When AI got a body, the incidents got physical.

Software has CVE/NVD. General AI has the AI Incident Database. Physical AI has had no single index — robot and vision-language-action security events are scattered across CVE records, CISA advisories, and arXiv. This is that index: every entry independently verifiable, each mapped to the Embodied AI Security Top 10.

7 verified entriesCVE · CISA · arXiv · pressLiving index — sourced only
Embodied AI security incidents · newest first · each links to its primary source and EAI mapping
DateIncidentMaps toSource
2026-05
Command injection in Universal Robots PolyScope 5
Unauthenticated OS command injection → controller RCE · CVSS 9.8
Universal Robots cobot controllers (PolyScope 5 < 5.25.1) — CISA advisory ICSA-26-134-17: an unauthenticated attacker with network access to the Dashboard Server executes commands on the robot controller — enough to alter safety configurations or manipulate physical movement.
CISA ICSA-26-134-17 →
2026-04
Unauthenticated RCE in Hugging Face LeRobot
Unsafe pickle deserialization over unauthenticated gRPC · CVSS 9.8
LeRobot async-inference PolicyServer (the default open VLA stack, 21.5k★) — CVE-2026-25874: any attacker who can reach the PolicyServer port runs arbitrary code on the host — a server that sits directly in the control path and whose outputs govern actuator commands on the robot's joints.
CVE-2026-25874 (Resecurity) →
2025-11
AttackVLA / BadVLA — targeted action hijack & backdoors
Targeted action-sequence hijack and implanted backdoors · Research
Vision-language-action robot policies — Drove a real robot through an attacker-specified action sequence, and showed backdoors that trigger a chosen motion on a hidden cue — the danger is in the trajectory, not the words.
arXiv:2511.12149 →
2025-09
FreezeVLA — adversarial policy paralysis
Adversarial-image freeze (no-op / paralysis) · Research
Open vision-language-action policies — Reported roughly 76% paralysis attack-success rate: an adversarial image freezes the policy into inaction — an availability failure that a single task-success metric hides.
arXiv:2509.19870 →
2025-09
UniPwn — Unitree Go2 / G1 exploit chain
Unauthenticated comms/BLE exploit → RCE, wormable · Real-world
Unitree quadruped & humanoid robots — An unauthenticated exploit chain against widely-deployed Unitree robots enabling remote code execution and self-propagation, alongside separately-reported covert telemetry from the same platform.
IEEE Spectrum →
2024-10
RoboPAIR — jailbreaking LLM-controlled robots
Automated policy / instruction jailbreak · Research
LLM-driven robots (Unitree Go2, Clearpath, an AV stack) — An automated jailbreak that reliably drove LLM-controlled robots to perform disallowed physical actions — the external validation Provael cites for EAI01.
arXiv:2410.13691 →
2019
Adversarial road stickers steer Tesla Autopilot
Physical adversarial-perception patch · Real-world
Tesla Autopilot (deployed driver-assist) — Researchers placed three small stickers on the road that steered Autopilot into the oncoming lane — the canonical proof that adversarial perception moves a real machine, not just a benchmark.
IEEE Spectrum →

These are the risks. Provael measures them.

The Embodied AI Security Top 10 turns this incident surface into a taxonomy — and Provael turns the taxonomy into a calibrated, reproducible attack-success rate for your own policy.