{"id":9623,"date":"2026-09-30T13:56:13","date_gmt":"2026-09-30T13:56:13","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9623"},"modified":"2026-09-30T13:56:13","modified_gmt":"2026-09-30T13:56:13","slug":"unsloths-model-picker-had-a-code-execution-problem","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9623","title":{"rendered":"Unsloth\u2019s model picker had a code-execution problem"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">True to its name, AI-model-training tool <a href=\"https:\/\/www.infoworld.com\/article\/4211593\/hands-on-with-unsloth-desktop-for-running-and-training-llms-locally.html\">Unsloth<\/a> would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines.<\/p>\n<p class=\"wp-block-paragraph\">Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a specially crafted model to get malicious code executed on a developer\u2019s system.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe code ran from nothing more than a metadata check,\u201d researcher <a href=\"https:\/\/www.linkedin.com\/in\/arielfogel\">Ariel Fogel<\/a> said in a <a href=\"https:\/\/www.pillar.security\/blog\/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution\">post on Pillar\u2019s blog<\/a>. \u201cReading the model\u2019s config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The code would run with the user\u2019s permission which, Fogel said, could expose proprietary training data, model artifacts, Hugging Face tokens, SSH keys, or accessible cloud credentials in an enterprise\u2019s AI development environment.<\/p>\n<p class=\"wp-block-paragraph\">Unsloth Studio is a web-based interface that is currently in beta, a status Unsloth\u2019s maintainers cited when they reportedly declined to publish a security advisory or have a CVE assigned to the flaw after <a href=\"https:\/\/unsloth.ai\/docs\/new\/changelog#id-2026-05-26\">fixing it in June<\/a>. Pillar contests that reasoning, pointing out that the vulnerable Studio code ships as part of the standard, generally available \u201cunsloth\u201d package on <a href=\"https:\/\/www.csoonline.com\/article\/4149905\/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html\">PyPI<\/a> and can be installed through an ordinary \u201cpip install unsloth\u201d without selecting a beta or prerelease version.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Transformers setting opened the door<\/h2>\n<p class=\"wp-block-paragraph\">Unsloth uses Hugging Face\u2019s <a href=\"https:\/\/www.csoonline.com\/article\/4181094\/hugging-face-transformers-rce-flaw-enables-stealthy-compromise-via-ai-model-configs.html?utm=hybrid_search#:~:text=trust_remote_code=false\">trust_remote-code<\/a> option, which allows a model to bring along its own Python code when needed.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s not necessarily dangerous by itself. Some legitimate Hugging Face models, including IBM Granite Speech and Vision, DeepSeek-OCR, ChatGLM, and earlier Qwen releases, need custom code to work properly, Fogel said.<\/p>\n<p class=\"wp-block-paragraph\">The problem was that Unsloth enabled the feature automatically during a routine model check rather than requiring the user to explicitly opt into running remote code. Before the patch, \u201ctrust_remote_code\u201d was turned on by default when Unsloth used Hugging Face\u2019s Transformers model-loading functionality to obtain information about a model being inspected.<\/p>\n<p class=\"wp-block-paragraph\">Unsloth\u2019s maintainers also pointed to Hugging Face\u2019s own malware scanning and warnings for models containing custom code as another reason for not treating the issue as a vulnerability. Pillar counters that Hugging Face\u2019s protections are mostly blocklists and that its proof-of-concept (PoC) code was not flagged when scanned but could have fetched a malicious second-stage payload only when processed by Unsloth.<\/p>\n<p class=\"wp-block-paragraph\">However, Fogel stressed that this is not a <a href=\"https:\/\/www.csoonline.com\/article\/4201361\/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html\">Hugging Face<\/a> vulnerability, but an issue with how Unsloth uses trust_remote_code.<\/p>\n<p class=\"wp-block-paragraph\"><a><\/a>The fix went beyond flipping the setting. Pillar initially recommended pinning trust_remote_code=False on the model-checking path because that path only needed to read declarative information from config.json. Unsloth\u2019s eventual fix went further.<\/p>\n<p class=\"wp-block-paragraph\">In version 2026.6.9, Studio was changed to no longer enable arbitrary model loading directly from Hugging Face and to not trust remote code from local model files. Fogel said it independently retested the version and confirmed that both the Hugging Face and local-directory attack paths were closed.<\/p>\n<p class=\"wp-block-paragraph\">Pillar urged users to upgrade to the fixed version, even if they never launch Studio and only use Unsloth core. Additionally, the company advised to audit LLM workflows for unnecessary occurrences of trust_remote_code=True.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe time-to-exploit for attackers keeps shrinking, because automated repo scanning, agentic exploitation, and organized supply-chain campaigns can weaponize a benign-looking auto_map module even faster than before the adoption of AI,\u201d Fogel warned.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.infoworld.com\/article\/4228904\/unsloths-model-picker-had-a-code-execution-problem.html\">InfoWorld<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9624,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9623","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9623"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9623"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9623\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9624"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}