Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

A sloth hanging from a tree
Source: webguzs via Getty Images

Unsloth has fixed a vulnerability in its Web user interface (UI) front end that exposed users to arbitrary code execution through malicious models.

Pillar Security's Ariel Fogel published a blog post today covering a flaw in Unsloth Studio. Unsloth Studio is the Web UI front end for Unsloth, a popular open source library used for fine-tuning and quantizing large language models (LLMs). According to the blog post, selecting a malicious model in Unsloth Studio could cause it to execute Python code shipped within the model's Hugging Face repository.

"The code ran from nothing more than a metadata check. Reading the model's config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference — the act of inspecting a model was enough to run its code," Fogel wrote.

As the code ran with user permission, Fogel wrote that an attack utilizing this flaw targeting an enterprise AI development environment could expose proprietary training data, model artifacts, and a number of credentials tied to the compromised process, such as cloud logins or SSH keys.

Related:Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

"An attacker could run code as the user, which could translate to stealing accessible data, altering models and training outputs, or using available credentials to access other systems," he wrote. "An internal experimentation environment can hold sensitive data and privileged access even when it serves no production traffic."

Fogel tells Dark Reading that Pillar has seen no evidence of real-world exploitation or malicious model repositories targeting this particular configuration mechanism to date, though he emphasizes that other malicious campaigns have leaned on malicious models uploaded to Hugging Face.

A Problematic Setting at the Center

Pillar traced the flaw to Unsloth Studio's use of the "trust_remote_code=True" setting while checking a model's configuration. The setting allowed the underlying "Transformers" library to download and execute custom Python code referenced by the model's config.json, even before the model itself was loaded.

Pillar Security reported the flaw to Unsloth in early June, and Unsloth addressed the issue later that month in update 2026.6.9. Pillar tested the attack vector and confirmed it was closed. While Fogel credited Unsloth's maintainers for a fast response, the blog post claimed that Unsloth disputed aspects of the security assessment, "citing that Hugging Face's malware scanning was an adequate control on the attack surface, and that the Studio, which was technically listed as being in beta, should be excluded from consideration."

Related:'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

The security vendor disagreed, arguing that Unsloth's claims fail to address Studio’s automatic execution of repository code. No CVE was assigned after Unsloth declined to publish the proposed security advisory, according to Pillar.

Dark Reading attempted to contact Unsloth through X but has received no response by press time.

Treat "trust_remote_code" as Untrusted Data

Pillar recommended that users upgrade Unsloth Studio to 2026.6.9 or later, and more broadly to "treat model repositories you load using transformers library trust_remote_code as untrusted code rather than data, and make sure the tools in your pipeline never enable it on your behalf."

As the blog author points out, there are use cases for the setting, but this is far from the first time it has been at the center of a vulnerability like this, even this year (see LMDeploy bug CVE-2026-46432, vLLM bug CVE-2026-4944, and InstructLab bug CVE-2026-6859).

Fogel tells Dark Reading the recurrence of this issue suggests a systemic gap in how machine learning tools handle executable model content. Developers build useful workflows around artifacts that users generally think of as data, but those artifacts can also supply code. When a tool silently enables trust_remote_code, Fogel explains, it makes a consequential security decision on the user's behalf.

Related:Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'

"What makes the Unsloth case particularly concerning," he says, "is that the boundary was crossed during an action users reasonably understood as inspection."

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: DarkReading