Unsloth’s model picker had a code-execution problem
- Published
- Record updated
Summary
Pillar Security found that selecting a model in Unsloth Studio made the application download and execute Python code from the model repository, with no weights loaded or inference run. The code ran with the user's permissions, which could expose training data, Hugging Face tokens, SSH keys and cloud credentials. Unsloth's maintainers declined to issue an advisory or CVE, citing Studio's beta status, and fixed the issue in June.
Mitigation
In version 2026.6.9, Studio no longer enables arbitrary model loading directly from Hugging Face and no longer trusts remote code from local model files. Pillar urges users to upgrade to the fixed version, even if they only use Unsloth core, and to audit LLM workflows for unnecessary occurrences of trust_remote_code=True.
Related items
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- InfoRolling the cyber dice with open-source and open-weight AI modelsSame vendor · CSO Online
- InfoCalifornia issues investigative subpoena to OpenAI over rogue agents’ hackingSame vendor · The Guardian Technology
- InfoSen. Hawley: OpenAI CEO Sam Altman declined to testify at rogue AI hearingSame vendor · CNBC Technology
- Medium“We’re not going to shoot ourselves in the foot” over hack fallout, says OpenAI’s chief research officerSame vendor · MIT Technology Review