- Selecting a model caused the backend to download and run Python code from its Hugging Face repository.
- Reading config.json could trigger the exploit before the backend loaded weights or ran inference.
- The affected code shipped in the standard unsloth package and could arrive through an ordinary pip install.
On this page
Model inspection triggered code execution
Selecting a model caused Unsloth Studio’s backend to download and run Python code shipped inside that model’s Hugging Face repository.
Reading a model’s config.json was enough to trigger the exploit. The backend did not need to load weights or run inference.
The code ran with the user’s permissions in the Studio backend process, and exploitation required running Studio and selecting an attacker-controlled model.
Earlier coverage: Research Reveals SQL Copilot Flaw CVE-2026-65669 Can Turn DB Users Into Admins.
Fact check
| Claim | Source | Status |
|---|---|---|
| Pillar Security found an arbitrary-code-execution vulnerability in Unsloth Studio. | Pillar Security, via pillar.security | Confirmed |
| Selecting a model caused Unsloth Studio’s backend to download and run Python code from the model’s Hugging Face repository. | Pillar Security, via pillar.security | Confirmed |
| Reading a model’s config.json was enough to trigger the exploit before the backend loaded weights or ran inference. | Pillar Security, via pillar.security | Confirmed |
| The attacker’s code ran with the user’s permissions in the Studio backend process. | Pillar Security, via pillar.security | Confirmed |
| Exploitation required running Studio and selecting an attacker-controlled model. | Pillar Security, via pillar.security | Confirmed |
| The affected code shipped in the standard unsloth package and could be received through an ordinary pip install. | Pillar Security, via pillar.security | Confirmed |
| Unsloth maintainers shipped a fix on 18 June 2026. | Pillar Security, via pillar.security | Confirmed |
| Pillar Security independently retested version 2026.6.9 and confirmed that the attack vector was closed. | Pillar Security, via pillar.security | Confirmed |
| Pillar Security said no CVE had been assigned. | Pillar Security, via pillar.security | Confirmed |
Could not verify
Whether the vulnerability was exploited in the wild.
How many Unsloth Studio users or installations were affected.
Whether Unsloth issued a public advisory or independently confirmed the technical findings.
Whether the vulnerability received a CVE assignment after the report was published.
What to do now
- Upgrade Unsloth Studio to version 2026.6.9 or later.
- Treat model repositories loaded using transformers trust_remote_code as untrusted code rather than data.
- Ensure pipeline tools never enable trust_remote_code on your behalf.
FAQ
What triggered the exploit?
Selecting an attacker-controlled model while running Studio triggered the exploit. Reading config.json was enough, before weights were loaded or inference ran.
What version closes the attack vector?
Pillar Security said its retest of version 2026.6.9 confirmed that the attack vector was closed.
Has a CVE been assigned?
Pillar Security said no CVE has been assigned.
What permissions did the code receive?
The attacker’s code ran with the user’s permissions in the Studio backend process.



