// AI threat desk · 2 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesMediumUNSLOTHCVSS not assigned

Unsloth Studio vulnerability let model selection run Python code

Pillar Security found arbitrary code execution in Unsloth Studio. Unsloth shipped a fix on June 18, 2026, and version 2026.6.9 closed the attack vector.

stock image, not from the event
File photo: stock image, not from the event. Photo: rawpixel (CC0)
Key takeaways
  • Selecting a model caused the backend to download and run Python code from its Hugging Face repository.
  • Reading config.json could trigger the exploit before the backend loaded weights or ran inference.
  • The affected code shipped in the standard unsloth package and could arrive through an ordinary pip install.
On this page

Model inspection triggered code execution

Selecting a model caused Unsloth Studio’s backend to download and run Python code shipped inside that model’s Hugging Face repository.

Reading a model’s config.json was enough to trigger the exploit. The backend did not need to load weights or run inference.

The code ran with the user’s permissions in the Studio backend process, and exploitation required running Studio and selecting an attacker-controlled model.

Earlier coverage: Research Reveals SQL Copilot Flaw CVE-2026-65669 Can Turn DB Users Into Admins.

Fact check

ClaimSourceStatus
Pillar Security found an arbitrary-code-execution vulnerability in Unsloth Studio.Pillar Security, via pillar.securityConfirmed
Selecting a model caused Unsloth Studio’s backend to download and run Python code from the model’s Hugging Face repository.Pillar Security, via pillar.securityConfirmed
Reading a model’s config.json was enough to trigger the exploit before the backend loaded weights or ran inference.Pillar Security, via pillar.securityConfirmed
The attacker’s code ran with the user’s permissions in the Studio backend process.Pillar Security, via pillar.securityConfirmed
Exploitation required running Studio and selecting an attacker-controlled model.Pillar Security, via pillar.securityConfirmed
The affected code shipped in the standard unsloth package and could be received through an ordinary pip install.Pillar Security, via pillar.securityConfirmed
Unsloth maintainers shipped a fix on 18 June 2026.Pillar Security, via pillar.securityConfirmed
Pillar Security independently retested version 2026.6.9 and confirmed that the attack vector was closed.Pillar Security, via pillar.securityConfirmed
Pillar Security said no CVE had been assigned.Pillar Security, via pillar.securityConfirmed

Could not verify

Whether the vulnerability was exploited in the wild.

How many Unsloth Studio users or installations were affected.

Whether Unsloth issued a public advisory or independently confirmed the technical findings.

Whether the vulnerability received a CVE assignment after the report was published.

What to do now

  1. Upgrade Unsloth Studio to version 2026.6.9 or later.
  2. Treat model repositories loaded using transformers trust_remote_code as untrusted code rather than data.
  3. Ensure pipeline tools never enable trust_remote_code on your behalf.

FAQ

What triggered the exploit?

Selecting an attacker-controlled model while running Studio triggered the exploit. Reading config.json was enough, before weights were loaded or inference ran.

What version closes the attack vector?

Pillar Security said its retest of version 2026.6.9 confirmed that the attack vector was closed.

Has a CVE been assigned?

Pillar Security said no CVE has been assigned.

What permissions did the code receive?

The attacker’s code ran with the user’s permissions in the Studio backend process.

Sources

  1. Look, Don't Load: Model Inspection in Unsloth Studio Leads to Critical Arbitrary Code Execution, Pillar SecurityPrimary
Explore with AI