Tech News
← Home  ·  All topics

Pillar Security

1 GoKawiil brief on this topic

Unsloth patches Unsloth Studio flaw allowing code execution via malicious model metadata

Security researcher Ariel Fogel of Pillar Security disclosed a vulnerability in Unsloth Studio, the web interface for the popular open-source LLM fine-tuning library Unsloth, that let a malicious Hugging Face model execute arbitrary Python code simply by having its config.json inspected. The flaw stemmed from Unsloth Studio's use of a 'trust_remote_code=True' setting in the Transformers library, meaning no model weights needed to load or run for the exploit to trigger. Unsloth has since fixed the issue.