www.darkreading.com 29 Sept 2026, 21:08 UTC

Unsloth Studio Flaw Let Malicious AI Models Run Python Code

CyberSIXT Evidence Panel Source marked as original reporting

A published vulnerability in Unsloth Studio, the web UI front end for Unsloth’s large language model tooling, allowed malicious AI models to run arbitrary Python code during a model inspection. The flaw hinged on the trust_remote_code=True setting used when checking a model’s configuration, which permitted the Transformers library to download and execute code referenced by a model’s config[.]json even before the model weights were loaded. This meant that simply inspecting a model could trigger code execution with the user’s permissions.

Pillar Security’s Ariel Fogel highlighted the issue, noting that the attack could expose proprietary training data, model artifacts, and credentials such as cloud logins or SSH keys within an internal experimentation environment. Pillar tested the vector and confirmed that Unsloth Studio version 2026.6.9 or later mitigates the flaw, while Unsloth initially disputed aspects of the security assessment. No CVE has been issued for this vulnerability.

At present, Dark Reading reports no evidence of real-world exploitation or malicious Hugging Face repositories targeting this specific configuration mechanism to date.

The recommended response is to upgrade to Unsloth Studio 2026.6.9 or later and treat trust_remote_code usage as untrusted, applying caution in pipelines that load repository code. The broader takeaway emphasizes a recurring risk in ML tooling: automated execution of executable model content can occur even during data-like actions such as inspection, underscoring the need for stricter controls around remote code execution in model repositories.

View full article

Article by CyberSIXT