Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model repository to execute attacker-controlled Python code simply by a user selecting or inspecting it.
Unsloth resolved the issue in version 2026.6.9, and users running Studio are urged to update immediately.
Unsloth Fixes Arbitrary Code Execution Flaw
Security researcher Ariel Fogel from Pillar Security discovered that Unsloth Studio’s backend had the setting `trust_remote_code=True` enabled by default. This occurred during the configuration and capabilities check of a selected Hugging Face model.
This vulnerability enabled an attacker to insert an `auto_map` field within a repository’s `config.json`. This field could direct the Hugging Face Transformers library to custom Python files stored in the repository.
When Studio queried the model configuration, it could automatically fetch and import the attacker-controlled Python module without downloading model weights, initiating inference, starting training, or receiving explicit user permission to execute remote code. Consequently, a metadata check, typically considered a low-risk operation, became an execution trigger.
The vulnerable code had `trust_remote_code=True` set as the default for the configuration-loading routine in the Studio backend. Model capability checks inherited this unsafe setting, while another path related to Transformers explicitly hardcoded remote-code trust. The vulnerability could be accessed through Studio’s model configuration and vision-check API endpoints.
The executed code ran under the Studio backend process’s permissions. In enterprise AI development environments, this could allow attackers to access Hugging Face tokens, cloud credentials, SSH keys, proprietary datasets, model weights, training outputs, and experiment configurations.
An attacker who executed code on a machine used for fine-tuning or serving models could steal data, modify model files, poison training artifacts, maintain access, or leverage available credentials to infiltrate deeper into an organization’s environment.
The vulnerability did not require Studio to be publicly accessible; a logged-in user selecting a malicious repository in a local Studio deployment could still trigger the execution. Shared deployments, cloud notebook systems, and configurations bound to 0.0.0.0 could widen the potential impact.
The `trust_remote_code=True` option is a legitimate Transformers capability used by some models that incorporate custom architectures, tokenizers, or inference implementations. However, enabling this option alters the security model: a model repository becomes not just a collection of weights and configuration data but also a potential source of executable code.
Fogel’s proof of concept demonstrated that a carefully crafted configuration could invoke a harmless action, such as opening a calculator and creating a file on the host. In the hands of a real attacker, this could lead to credential theft, downloading secondary payloads, data exfiltration, or discovering further environment details.
While Hugging Face malware scanning can detect some suspicious artifacts, it is not a complete execution-security control. The core issue stems from Studio’s automatic trust in and execution of repository-provided code during the model inspection workflow.
Unsloth released a fix in version 2026.6.9 after the issue was reported. The updated implementation of Studio no longer allows arbitrary Hugging Face model loading through the vulnerable inspection path and restricts trust of remote code from local model files. Independent testing has confirmed that the identified attack vector has been closed.
Organizations should upgrade Studio to version 2026.6.9 or later and examine every instance where `trust_remote_code=True` may be enabled in their AI development pipelines.
Model repositories that require remote code should be treated as untrusted software, loaded only with explicit user approval, pinned to known revisions, and isolated from sensitive credentials and production systems.
No CVE has been assigned to this vulnerability because Unsloth reportedly did not publish an advisory for the beta Studio feature. Nonetheless, the affected code was included in the standard unsloth package, so teams using Studio must apply the patch.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC





