Skip to content
Unsloth Studio Vulnerability Enables Code Execution via Model Inspection

Unsloth Studio Vulnerability Enables Code Execution via Model Inspection

First seen 30 Sep 2026, 00:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 00:06 UTC
  • •Unsloth Studio's flaw allows arbitrary code execution during model inspection.
  • •The vulnerability affects users with permissions in enterprise AI environments.
  • •Pillar Security reported the flaw, which Unsloth has since patched.

A critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, allows arbitrary code execution through model inspection. This flaw arises from the 'trust_remote_code=True' setting, which permits execution of Python code from a model's Hugging Face repository upon merely inspecting its metadata. The code runs with the user's permissions, potentially exposing sensitive data, model artifacts, and credentials in enterprise environments. While Unsloth has patched the vulnerability, there are disputes regarding the adequacy of security measures, with Pillar Security emphasizing the risks of untrusted code execution. No evidence of real-world exploitation has been reported, but the potential for significant impact remains. The vulnerability is associated with CVE-2026-46432, published on June 9, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-07
CVE-2026-1839 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-22
CVE-2026-6859 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-28
CVE-2026-4944 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
CVE-2026-46432 published
A vulnerability in Unsloth Studio was disclosed, allowing arbitrary code execution during model inspection.
Pillar Security
2026-06-30
Unsloth patches vulnerability
Unsloth addressed the code execution flaw in update 2026.6.9, following a report from Pillar Security.
Darkreading
2026-09-29
Pillar Security publishes blog post
Pillar Security detailed the vulnerability and its implications for enterprise users, highlighting the risks associated with untrusted code execution.
Pillar Security

More articles in this cluster (2)

Following this threat?

Track CVE-2026-1839 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed