Unsloth patches Unsloth Studio flaw allowing code execution via malicious model metadata
Security researcher Ariel Fogel of Pillar Security disclosed a vulnerability in Unsloth Studio, the web interface for the popular open-source LLM fine-tuning library Unsloth, that let a malicious Hugging Face model execute arbitrary Python code simply by having its config.json inspected. The flaw stemmed from Unsloth Studio's use of a 'trust_remote_code=True' setting in the Transformers library, meaning no model weights needed to load or run for the exploit to trigger. Unsloth has since fixed the issue.
GoKawiil's interpretation of the reporting above, not reported fact.
Because the exploit fired during a routine metadata check rather than actual model use, it suggests inspecting a model could be as risky as running it, potentially undermining common vetting practices in AI development pipelines. Fogel warns that in enterprise settings, such code execution could expose proprietary training data, credentials, and cloud or SSH access tied to the affected process. Pillar says it has not seen evidence of this specific flaw being exploited in the wild, though it notes malicious models on Hugging Face have been used in other attacks.
- Unsloth Studio's use of 'trust_remote_code=True' let malicious models run code just by being inspected, not loaded.
- The flaw could have exposed training data, model artifacts, and credentials like cloud logins or SSH keys.
- Unsloth has released a fix; Pillar Security says no known exploitation of this specific issue has occurred yet.
Source: darkreading.com — Alexander Culafi, 2026-09-29
Published there as: “Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.