Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OperTraitors Tool Exposes Critical Kubernetes Privilege Escalation Paths
September 30, 2026
AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX
September 30, 2026
Critical RCE in Unsloth Studio Lets Malicious Hugging Face Models Execute Code
September 30, 2026
Home/Vulnerabilities/Critical RCE in Unsloth Studio Lets Malicious Hugging Face Models Execute Code
Vulnerabilities

Critical RCE in Unsloth Studio Lets Malicious Hugging Face Models Execute Code

Key Takeaways A critical remote code execution (RCE) vulnerability was discovered in Unsloth Studio, a popular browser-based interface for fine-tuning large language models. The flaw allowed...

Sarah simpson
Sarah simpson
September 30, 2026 4 Min Read
2 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability was discovered in Unsloth Studio, a popular browser-based interface for fine-tuning large language models.
  • The flaw allowed malicious Hugging Face models to execute arbitrary Python code on a user’s system simply by being selected in the Studio interface.
  • The vulnerability, which did not receive a CVE, has been patched in Unsloth Studio version 2026.6.9, and users are urged to upgrade immediately.
  • Exploitation could lead to theft of sensitive credentials, data manipulation, or further compromise of AI development infrastructure.

A significant security flaw in Unsloth Studio, a widely used platform for optimizing large language models (LLMs), permitted unauthorized Python code execution through specially crafted Hugging Face models. The vulnerability, now resolved, enabled attackers to run arbitrary code on a user’s system merely by the user selecting a malicious model within the Studio’s browser-based interface.

Table Of Content

  • Key Takeaways
  • Understanding the Unsloth Studio RCE Flaw
  • The Danger of trust_remote_code=True
  • Potential Impact of Exploitation
  • What You Should Do

Unsloth, an open-source library renowned for its efficiency in fine-tuning and quantizing LLMs, offers the Studio component as a beta-stage, user-friendly graphical interface for streamlined model selection, training, and workflow management. The project’s influence within the AI ecosystem is substantial; Hugging Face ranks Unsloth as the third-largest producer of model derivatives on its Hub, trailing only Qwen and Google.

The critical flaw was addressed in Unsloth Studio version 2026.6.9. All users operating Studio installations are strongly advised to update without delay to mitigate the risk of compromise.

Understanding the Unsloth Studio RCE Flaw

The vulnerability stemmed from a misconfiguration within Unsloth Studio’s backend model-inspection process. When a user interacted with the interface to choose a Hugging Face model, Studio would perform a preliminary check of the model’s configuration before proceeding to load weights or initiate inference. Crucially, this code path inadvertently enabled the trust_remote_code=True setting by default.

The Danger of trust_remote_code=True

The trust_remote_code=True parameter is a powerful yet inherently risky setting within the Hugging Face Transformers library. It permits model repositories to include custom Python files alongside standard model weights and configuration data. When enabled, the config.json file within a repository can leverage the auto_map field to direct Transformers components, such as AutoConfig, to these local Python files. Consequently, the Transformers library will import and execute the repository-provided module.

In the vulnerable versions of Unsloth Studio, this execution occurred during what appeared to be a benign metadata inspection. An attacker could craft a malicious model repository containing a specially designed config.json. If a Studio user then selected this repository through the interface, the embedded malicious code would automatically execute within the Studio backend process.

Significantly, the victim did not need to perform any advanced actions like loading model weights, initiating training, starting inference, or explicitly approving remote code execution. The malicious code would run with the same permissions as the user operating Studio.

Potential Impact of Exploitation

On systems used for AI development, such an exploit could have severe ramifications. Attackers might gain unauthorized access to critical assets, including Hugging Face tokens, cloud provider credentials, SSH keys, proprietary datasets, valuable model artifacts, and sensitive training outputs. Furthermore, successful exploitation could enable attackers to tamper with local models, establish persistent access to the compromised system, or leverage accessible credentials to expand their reach into other infrastructure.

The vulnerable logic was integrated into the standard Unsloth Python package, not a separate, pre-release-only component. While exploitation required the victim to actively run Studio and select an attacker-controlled model, the affected code could be installed via a routine pip install unsloth command.

Pillar Security reported the issue privately to Unsloth’s maintainers in early June 2026. A patch was subsequently released on June 18. Researchers independently confirmed that version 2026.6.9 effectively closes both the vulnerable Hugging Face and local-directory model-loading pathways.

Despite the critical nature of the flaw, Unsloth’s maintainers opted not to publish a formal security advisory, citing Studio’s beta status, and therefore, no CVE identifier was assigned.

What You Should Do

  • Upgrade Unsloth Studio Immediately: All users of Unsloth Studio must upgrade to version 2026.6.9 or a later release to eliminate this critical vulnerability.
  • Exercise Caution with trust_remote_code=True: Security teams should treat any use of the trust_remote_code=True setting as equivalent to executing untrusted software, rather than a standard model-loading option.
  • Pin Model Repositories: Always pin model repositories to known, trusted revisions to prevent inadvertent loading of malicious or compromised versions.
  • Isolate Environments: Load and run models in isolated, sandboxed environments to contain potential exploits and limit their impact.
  • Limit Credential Access: Implement strict access controls and prevent long-lived, high-privilege credentials from being accessible within model loading or training environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Fortinet discovers SectopRAT variant in trojanized Windows software

Next Post

AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical OAuth Flaw in Microsoft Copilot Python SDK Exposes AI Agent Accounts
September 30, 2026
Critical Octopus Server Flaw CVE-2023-31446 Allows Remote Code Execution
September 30, 2026
OpenSSL Patches High-Severity Memory Leak Vulnerability
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us