Updated
Updated · InfoWorld · Sep 30
Unsloth Fixes Code-Execution Flaw in Version 2026.6.9 as Model Checks Ran Remote Python
Updated
Updated · InfoWorld · Sep 30

Unsloth Fixes Code-Execution Flaw in Version 2026.6.9 as Model Checks Ran Remote Python

3 articles · Updated · InfoWorld · Sep 30

Summary

  • Version 2026.6.9 closes a critical flaw that let Unsloth execute arbitrary Python code when a developer merely selected or inspected a model.
  • Pillar Security said the bug came from Unsloth automatically enabling Hugging Face's trust_remote_code during routine metadata checks, so reading config.json could trigger code without loading weights or running inference.
  • That code ran with the user's privileges, potentially exposing training data, model artifacts, Hugging Face tokens, SSH keys and reachable cloud credentials in enterprise AI environments.
  • Unsloth's fix blocks direct arbitrary model loading from Hugging Face in Studio and stops trusting remote code from local model files; Pillar said retesting confirmed both attack paths were closed.
  • Pillar urged all users—including those using only the core package—to upgrade, noting the vulnerable Studio code shipped in the standard PyPI unsloth package and warning that AI-driven supply-chain attacks are accelerating.

Insights

Could a simple click on a Hugging Face model really run attacker code, and what did Unsloth Studio change to stop it?
Why is `trust_remote_code=True` becoming an AI supply-chain hazard, even when a tool is only inspecting model metadata?
If model browsing can expose SSH keys, tokens, and training data, how should teams redesign AI workflows before the next poisoned repository appears?