Wednesday, September 30, 2026

Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models

Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model repository to execute attacker-controlled Python code simply by a user selecting or inspecting it.

Unsloth resolved the issue in version 2026.6.9, and users running Studio are urged to update immediately.

Unsloth Fixes Arbitrary Code Execution Flaw

Security researcher Ariel Fogel from Pillar Security discovered that Unsloth Studio’s backend had the setting `trust_remote_code=True` enabled by default. This occurred during the configuration and capabilities check of a selected Hugging Face model.

This vulnerability enabled an attacker to insert an `auto_map` field within a repository’s `config.json`. This field could direct the Hugging Face Transformers library to custom Python files stored in the repository.

When Studio queried the model configuration, it could automatically fetch and import the attacker-controlled Python module without downloading model weights, initiating inference, starting training, or receiving explicit user permission to execute remote code. Consequently, a metadata check, typically considered a low-risk operation, became an execution trigger.

The vulnerable code had `trust_remote_code=True` set as the default for the configuration-loading routine in the Studio backend. Model capability checks inherited this unsafe setting, while another path related to Transformers explicitly hardcoded remote-code trust. The vulnerability could be accessed through Studio’s model configuration and vision-check API endpoints.

The executed code ran under the Studio backend process’s permissions. In enterprise AI development environments, this could allow attackers to access Hugging Face tokens, cloud credentials, SSH keys, proprietary datasets, model weights, training outputs, and experiment configurations.

An attacker who executed code on a machine used for fine-tuning or serving models could steal data, modify model files, poison training artifacts, maintain access, or leverage available credentials to infiltrate deeper into an organization’s environment.

The vulnerability did not require Studio to be publicly accessible; a logged-in user selecting a malicious repository in a local Studio deployment could still trigger the execution. Shared deployments, cloud notebook systems, and configurations bound to 0.0.0.0 could widen the potential impact.

The `trust_remote_code=True` option is a legitimate Transformers capability used by some models that incorporate custom architectures, tokenizers, or inference implementations. However, enabling this option alters the security model: a model repository becomes not just a collection of weights and configuration data but also a potential source of executable code.

Fogel’s proof of concept demonstrated that a carefully crafted configuration could invoke a harmless action, such as opening a calculator and creating a file on the host. In the hands of a real attacker, this could lead to credential theft, downloading secondary payloads, data exfiltration, or discovering further environment details.

While Hugging Face malware scanning can detect some suspicious artifacts, it is not a complete execution-security control. The core issue stems from Studio’s automatic trust in and execution of repository-provided code during the model inspection workflow.

Unsloth released a fix in version 2026.6.9 after the issue was reported. The updated implementation of Studio no longer allows arbitrary Hugging Face model loading through the vulnerable inspection path and restricts trust of remote code from local model files. Independent testing has confirmed that the identified attack vector has been closed.

Organizations should upgrade Studio to version 2026.6.9 or later and examine every instance where `trust_remote_code=True` may be enabled in their AI development pipelines.

Model repositories that require remote code should be treated as untrusted software, loaded only with explicit user approval, pinned to known revisions, and isolated from sensitive credentials and production systems.

No CVE has been assigned to this vulnerability because Unsloth reportedly did not publish an advisory for the beta Studio feature. Nonetheless, the affected code was included in the standard unsloth package, so teams using Studio must apply the patch.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks

A newly documented Android banking trojan named RATHat is...

SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets

A newly analyzed SectopRAT campaign demonstrates how threat actors...

OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext

OpenSSL has announced a high-severity vulnerability in its Datagram...

OpenAI Cancels GPT-6.1 Astra Release Over Internal Safety Concerns

OpenAI has canceled the planned October release of GPT-6.1...

Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover

Security researchers have disclosed a high-severity vulnerability in Anthropic’s...

Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code

Octopus Deploy has announced a high-severity vulnerability in Octopus...

Related Articles

Recent News