When AI got a body, the incidents got physical.
Software has CVE/NVD. General AI has the AI Incident Database. Physical AI has had no single index - robot and vision-language-action security events are scattered across CVE records, CISA advisories, and arXiv. This is that index: every entry independently verifiable, each mapped to the Embodied AI Security Top 10.
| Date | Incident | Maps to | Source |
|---|---|---|---|
| 2026-08 | UniBLEed - two root-RCE chains in the Unitree G1 EDU, one reachable from Bluetooth range with no pairing Chained remote code execution: BLE GATT + WiFi provisioning (CVE-2026-76640) and a DDS bridge + path traversal (CVE-2026-76639) · CVE (2), both PUBLISHED 2026-08-27 Unitree G1 EDU humanoid, firmware through 1.5.2 - the Locomotion PC, which runs motors, cameras, audio and voice as root - Disclosed 27 August 2026 by Olivier Laflamme. CVE-2026-76640 needs only Bluetooth proximity and no pairing or credentials: crafted writes to an unprotected GATT characteristic overflow a fixed 500-byte SSID accumulator with a 1050-byte payload across BLE connections, corrupting an adjacent mainloop function-pointer entry that the cleanup path later invokes with attacker-controlled data through system() as uid 0. CVE-2026-76639 is network-adjacent: an unauthenticated WebRTC-to-DDS bridge on TCP 9991, a world-readable static AES-128 key, and path traversal in the chat_go knowledge upload combine to plant a payload in bashrunner’s script directory and run it as root. Both records were read at cve.org before this entry was published; both are PUBLISHED, assigned by VulnCheck, and name Unitree Robotics G1 EDU through 1.5.2. THIS IS THE CLASS PROVAEL DOES NOT TEST. Provael attacks a policy through the instructions and observations it receives; nothing here touches a policy. The entry point is a radio, the bug is a missing bounds check in C, and the outcome is uid 0 on the computer the policy happens to run on — EAI07, which the registry marks out of scope for a VLA red-teamer by design, and which is assessed with IEC 62443 and ATT&CK-for-ICS methods and CVE scanning against the robot’s own stack. A clean Provael run says nothing whatsoever about this. That boundary is a large part of why this index exists: the risks a policy scanner cannot see still belong on the map. | Laflamme, UniBLEed (researcher write-up); CVE-2026-76639 / CVE-2026-76640 → | |
| 2026-08 | DURA - a diffusion-optimised patch that works when printed, and needs only the robot’s emitted actions Adversarial patch optimised along a diffusion latent trajectory, white-box and black-box · Research OpenVLA-7B and pi0-FAST on LIBERO, plus a real Franka arm - Reports 100% ASR under white-box access across all four LIBERO suites in both the simulated and physical patch settings, 86.0% and 79.3% black-box, and 77% from a patch covering 2% of the image (99% at 5%), against 23.5% benign and 39.5% clean-patch baselines. What is new is the black-box variant: it needs only the victim’s emitted actions, so an observable action stream is itself an attack surface rather than just an output. Third-party work - Provael did not run it, and unlike most entries here it was demonstrated on physical hardware, with a printed patch held in the arm’s camera view. | arXiv:2608.10393 → | |
| 2026-08 | DRIFT - flow-matching robustness reported as an artefact of how it was measured Universal gripper patch optimised against the first denoising step · Research Flow-matching VLA policies (pi0, pi0.5) - Reports that the adversarial robustness flow-matching policies were credited with "is largely illusory: it stems from prior attacks ignoring the multi-step denoising ODE", and that attacking only the first denoising step beats attacking a wider window. Not a deployed incident and no robot was harmed: a white-box result on off-the-shelf policies in simulation. | arXiv:2608.03207 → | |
| 2026-08 | AGSD and SARF - attention-hijacking patch, and a defense measured on real hardware Printable patch that hijacks action-to-vision attention, plus a fine-tuning defense · Research OpenVLA on LIBERO, and a physical PiPER manipulator - AGSD drives OpenVLA to a 100% failure rate under attack; the paired SARF defense cuts that to 14.2-56.8% and, on a real PiPER arm, lifts average success under attack from 23.0% to 65.0%. Listed because the defense half carries a physical-robot number - the kind of evidence Provael does not have for any family. | arXiv:2608.03231 → | |
| 2026-05 | Command injection in Universal Robots PolyScope 5 Unauthenticated OS command injection → controller RCE · CVSS 9.8 Universal Robots cobot controllers (PolyScope 5 < 5.25.1) - CISA advisory ICSA-26-134-17: an unauthenticated attacker with network access to the Dashboard Server executes commands on the robot controller - enough to alter safety configurations or manipulate physical movement. | CISA ICSA-26-134-17 → | |
| 2026-04 | Unauthenticated RCE in Hugging Face LeRobot Unsafe pickle deserialization over unauthenticated gRPC · CVSS 9.8 LeRobot async-inference PolicyServer (the default open VLA stack, 21.5k★) - CVE-2026-25874: any attacker who can reach the PolicyServer port runs arbitrary code on the host - a server that sits directly in the control path and whose outputs govern actuator commands on the robot's joints. | CVE-2026-25874 (Resecurity) → | |
| 2025-11 | AttackVLA / BadVLA - targeted action hijack & backdoors Targeted action-sequence hijack and implanted backdoors · Research Vision-language-action robot policies - Drove a real robot through an attacker-specified action sequence, and showed backdoors that trigger a chosen motion on a hidden cue - the danger is in the trajectory, not the words. | arXiv:2511.12149 → | |
| 2025-09 | FreezeVLA - adversarial policy paralysis Adversarial-image freeze (no-op / paralysis) · Research Open vision-language-action policies - Reported roughly 76% paralysis attack-success rate: an adversarial image freezes the policy into inaction - an availability failure that a single task-success metric hides. | arXiv:2509.19870 → | |
| 2025-09 | UniPwn - Unitree Go2 / G1 exploit chain Unauthenticated comms/BLE exploit → RCE, wormable · Real-world Unitree quadruped & humanoid robots - An unauthenticated exploit chain against widely-deployed Unitree robots enabling remote code execution and self-propagation, alongside separately-reported covert telemetry from the same platform. | IEEE Spectrum → | |
| 2024-10 | RoboPAIR - jailbreaking LLM-controlled robots Automated policy / instruction jailbreak · Research LLM-driven robots (Unitree Go2, Clearpath, an AV stack) - An automated jailbreak that reliably drove LLM-controlled robots to perform disallowed physical actions - the external validation Provael cites for EAI01. | arXiv:2410.13691 → | |
| 2019 | Adversarial road stickers steer Tesla Autopilot Physical adversarial-perception patch · Real-world Tesla Autopilot (deployed driver-assist) - Researchers placed three small stickers on the road that steered Autopilot into the oncoming lane - the canonical proof that adversarial perception moves a real machine, not just a benchmark. | IEEE Spectrum → |
Inclusion is descriptive - not an endorsement, and not a claim of novelty. Sources are third-party and linked; where a CVE or CISA advisory exists it is cited directly. To propose an entry with a verifiable primary source, email hello@provael.com.
Full-text feed of every note, measured finding and tracked incident — including the null results. No account, nothing to unsubscribe from.
These are the risks. Provael measures them.
The Embodied AI Security Top 10 turns this incident surface into a taxonomy - and Provael turns the taxonomy into a reproducible attack-success rate for your own policy.