Back Darkreading Unsloth Studio Flaw Turns Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Unsloth has fixed a vulnerability in its Web user interface (UI) front end that exposed users to arbitrary code execution through malicious models.
Pillar Security's Ariel Fogel published a blog post today covering a flaw in Unsloth Studio. Unsloth Studio is the Web UI front end for Unsloth, a popular open source library used for fine-tuning and quantizing large language models (LLMs). According to the blog post, selecting a malicious model in Unsloth Studio could cause it to execute Python code shipped within the model's Hugging Face repository.
"The code ran from nothing more than a metadata check. Reading the model's config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference — the act of inspecting a model was enough to run its code," Fogel wrote .
As the code ran with user permission, Fogel wrote that an attack utilizing this flaw targeting an enterprise AI development environment could expose proprietary training data, model artifacts, and a number of credentials tied to the compromised process, such as cloud logins or SSH keys.
Related: Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
"An attacker could run code as the user, which could translate to stealing accessible data, altering models and training outputs, or using available credentials to access other systems," he wrote. "An internal experimentation environment can hold sensitive data and privileged access even when it serves no production traffic."
Fogel tells Dark Reading that Pillar has seen no evidence of real-world exploitation or malicious model repositories targeting this particular configuration mechanism to date, though he emphasizes that other malicious campaigns have leaned on malicious models uploaded to Hugging Face .
A Problematic Setting at the Center
Pillar traced the flaw to Unsloth Studio's use of the "trust_remote_code=True" setting while checking a model's configuration. The setting allowed the underlying "Transformers" library to download and execute custom Python code referenced by the model's config.json, even before the model itself was loaded.
Pillar Security reported the flaw to Unsloth in early June, and Unsloth addressed the issue later that month in update 2026.6.9. Pillar tested the attack vector and confirmed it was closed. While Fogel credited Unsloth's maintainers for a fast response, the blog post claimed that Unsloth disputed aspects of the security assessment, "citing that Hugging Face's malware scanning was an adequate control on the attack surface, and that the Studio, which was technically listed as being in beta, should be excluded from consideration."
Related: 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
The security vendor disagreed, arguing that Unsloth's claims fail to address Studio’s automatic execution of repository code. No CVE was assigned after Unsloth declined to publish the proposed security advisory, according to Pillar.
Dark Reading attempted to Unsloth through X but has received no response by press time.
Treat "trust_remote_code" as Untrusted Data
Pillar recommended that users upgrade Unsloth Studio to 2026.6.9 or later, and more broadly to "treat model repositories you load using transformers library trust_remote_code as untrusted code rather than data, and make sure the tools in your pipeline never enable it on your behalf."
As the blog author points out, there are use cases for the setting, but this is far from the first time it has been at the center of a vulnerability like this, even this year (see LMDeploy bug CVE-2026-46432, vLLM bug CVE-2026-4944, and InstructLab bug CVE-2026-6859).
Fogel tells Dark Reading the recurrence of this issue suggests a systemic gap in how machine learning tools handle executable model content. Developers build useful workflows around artifacts that users generally think of as data, but those artifacts can also supply code. When a tool silently enables trust_remote_code, Fogel explains, it makes a consequential security decision on the user's behalf.
Related: Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
"What makes the Unsloth case particularly concerning," he says, "is that the boundary was crossed during an action users reasonably understood as inspection."
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Chinese Hackers Hijack Notepad++ Updates for 6 Months
Trump Administration Rescinds Biden-Era Software Guidance
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
