Unsloth Fixes Code-Execution Flaw in Version 2026.6.9 as Model Checks Ran Remote Python
Updated
Updated · InfoWorld · Sep 30
Unsloth Fixes Code-Execution Flaw in Version 2026.6.9 as Model Checks Ran Remote Python
3 articles · Updated · InfoWorld · Sep 30
Summary
Version 2026.6.9 closes a critical flaw that let Unsloth execute arbitrary Python code when a developer merely selected or inspected a model.
Pillar Security said the bug came from Unsloth automatically enabling Hugging Face's trust_remote_code during routine metadata checks, so reading config.json could trigger code without loading weights or running inference.
That code ran with the user's privileges, potentially exposing training data, model artifacts, Hugging Face tokens, SSH keys and reachable cloud credentials in enterprise AI environments.
Unsloth's fix blocks direct arbitrary model loading from Hugging Face in Studio and stops trusting remote code from local model files; Pillar said retesting confirmed both attack paths were closed.
Pillar urged all users—including those using only the core package—to upgrade, noting the vulnerable Studio code shipped in the standard PyPI unsloth package and warning that AI-driven supply-chain attacks are accelerating.