When AI got a body, the incidents got physical.
Software has CVE/NVD. General AI has the AI Incident Database. Physical AI has had no single index — robot and vision-language-action security events are scattered across CVE records, CISA advisories, and arXiv. This is that index: every entry independently verifiable, each mapped to the Embodied AI Security Top 10.
| Date | Incident | Maps to | Source |
|---|---|---|---|
| 2026-05 | Command injection in Universal Robots PolyScope 5 Unauthenticated OS command injection → controller RCE · CVSS 9.8 Universal Robots cobot controllers (PolyScope 5 < 5.25.1) — CISA advisory ICSA-26-134-17: an unauthenticated attacker with network access to the Dashboard Server executes commands on the robot controller — enough to alter safety configurations or manipulate physical movement. | CISA ICSA-26-134-17 → | |
| 2026-04 | Unauthenticated RCE in Hugging Face LeRobot Unsafe pickle deserialization over unauthenticated gRPC · CVSS 9.8 LeRobot async-inference PolicyServer (the default open VLA stack, 21.5k★) — CVE-2026-25874: any attacker who can reach the PolicyServer port runs arbitrary code on the host — a server that sits directly in the control path and whose outputs govern actuator commands on the robot's joints. | CVE-2026-25874 (Resecurity) → | |
| 2025-11 | AttackVLA / BadVLA — targeted action hijack & backdoors Targeted action-sequence hijack and implanted backdoors · Research Vision-language-action robot policies — Drove a real robot through an attacker-specified action sequence, and showed backdoors that trigger a chosen motion on a hidden cue — the danger is in the trajectory, not the words. | arXiv:2511.12149 → | |
| 2025-09 | FreezeVLA — adversarial policy paralysis Adversarial-image freeze (no-op / paralysis) · Research Open vision-language-action policies — Reported roughly 76% paralysis attack-success rate: an adversarial image freezes the policy into inaction — an availability failure that a single task-success metric hides. | arXiv:2509.19870 → | |
| 2025-09 | UniPwn — Unitree Go2 / G1 exploit chain Unauthenticated comms/BLE exploit → RCE, wormable · Real-world Unitree quadruped & humanoid robots — An unauthenticated exploit chain against widely-deployed Unitree robots enabling remote code execution and self-propagation, alongside separately-reported covert telemetry from the same platform. | IEEE Spectrum → | |
| 2024-10 | RoboPAIR — jailbreaking LLM-controlled robots Automated policy / instruction jailbreak · Research LLM-driven robots (Unitree Go2, Clearpath, an AV stack) — An automated jailbreak that reliably drove LLM-controlled robots to perform disallowed physical actions — the external validation Provael cites for EAI01. | arXiv:2410.13691 → | |
| 2019 | Adversarial road stickers steer Tesla Autopilot Physical adversarial-perception patch · Real-world Tesla Autopilot (deployed driver-assist) — Researchers placed three small stickers on the road that steered Autopilot into the oncoming lane — the canonical proof that adversarial perception moves a real machine, not just a benchmark. | IEEE Spectrum → |
Inclusion is descriptive — not an endorsement, and not a claim of novelty. Sources are third-party and linked; where a CVE or CISA advisory exists it is cited directly. To propose an entry with a verifiable primary source, email hello@provael.com.
Get a note when a verified incident is added to the tracker, or a new finding ships. No spam.
These are the risks. Provael measures them.
The Embodied AI Security Top 10 turns this incident surface into a taxonomy — and Provael turns the taxonomy into a calibrated, reproducible attack-success rate for your own policy.