A critical vulnerability in Unsloth Studio, a popular open-source library for fine-tuning and quantizing large language models (LLMs), has been patched after researchers discovered that malicious AI models could execute arbitrary Python code during inspection. The flaw, which was reported to Unsloth in June and fixed in update 2026.6.9, allowed attackers to run custom code with user permission, potentially exposing sensitive data, model artifacts, and credentials.
The vulnerability stemmed from the “trust_remote_code=True” setting in Unsloth Studio’s Web UI front end, which allowed the underlying “Transformers” library to download and execute custom Python code referenced by a model’s configuration file. This code was executed even before the model itself was loaded, making it possible for an attacker to steal accessible data, alter models and training outputs, or use available credentials to access other systems.
The researchers at Pillar Security, who discovered the flaw, warned that an attack utilizing this vulnerability could have significant consequences in an enterprise AI development environment. They noted that internal experimentation environments can hold sensitive data and privileged access even when they serve no production traffic. In their blog post, Ariel Fogel wrote that “an attacker could run code as the user, which could translate to stealing accessible data, altering models and training outputs, or using available credentials to access other systems.”
While Pillar has seen no evidence of real-world exploitation or malicious model repositories targeting this particular configuration mechanism, they emphasized that other campaigns have leveraged malicious models uploaded to Hugging Face. The recurrence of similar vulnerabilities, such as the LMDeploy bug CVE-2026-46432 and vLLM bug CVE-2026-4944, suggests a systemic gap in how machine learning tools handle executable model content.
The fix is straightforward: users should upgrade Unsloth Studio to 2026.6.9 or later and treat model repositories loaded using the “trust_remote_code” setting as untrusted code rather than data. Pillar recommended that developers make sure their pipeline never enables this setting on their behalf, as it can lead to silent security decisions being made by tools.
The Unsloth Studio vulnerability serves as a reminder of the importance of secure development practices in machine learning and AI. As researchers continue to push the boundaries of what is possible with these technologies, they must also prioritize the security of these systems to prevent exploitation by malicious actors. By treating model repositories with caution and upgrading to patched versions, developers can help mitigate this risk and ensure that their work remains secure.
Source: Dark Reading — 2026-09-29