Security1 publisher2 min readPublished
Unsloth Studio executed a model's Python code during a routine config check
Unsloth fixed Studio in version 2026.6.9 after Pillar Security showed that reading a malicious model's config.json could run an attacker's Python code. Unsloth disputed parts of the finding and declined to publish an advisory, so no CVE was assigned.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Studio's model check called the Transformers library with trust_remote_code=True, which let it download and run custom Python referenced in config.json before any weights loaded.
- The code ran with the user's permissions, putting proprietary training data, model artifacts and credentials such as cloud logins and SSH keys within reach.
- Pillar reported the flaw in early June, Unsloth shipped the fix later that month, and Pillar confirmed the attack path was closed.
- The same setting was at the center of LMDeploy CVE-2026-46432, vLLM CVE-2026-4944 and InstructLab CVE-2026-6859 this year.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure On unpatched Studio installs, whoever publishes a Hugging Face repository chooses code that runs on the machine of anyone who browses to that model.
- constraint Without a CVE, scanners and patch dashboards keyed to CVE identifiers have nothing to flag, so finding pre-2026.6.9 Studio installs takes a manual version check.
- decision Pillar's advice makes trust_remote_code an install decision: any pipeline tool that sets the flag for the user has to be found and reviewed the way an untrusted package would be.
Studio is the web front end for Unsloth, an open source library for fine-tuning and quantizing large language models [1]. For the attack to work, the victim only has to select a malicious model in that interface [2]. "The code ran from nothing more than a metadata check. Reading the model's config.json was enough to trigger the exploit," Pillar Security's Ariel Fogel wrote in the disclosure post [3].
Fogel told Dark Reading that Pillar has seen no real-world exploitation and no malicious repositories aimed at this configuration mechanism [8]. He also said other campaigns have used malicious models uploaded to Hugging Face [8]. No actor has been tied to this flaw.
A working payload runs as the developer [5]. Fogel's list of outcomes included "altering models and training outputs" and using available credentials to reach other systems [6]. "An internal experimentation environment can hold sensitive data and privileged access even when it serves no production traffic," he wrote [7].
According to Pillar's post, Unsloth disputed the assessment, "citing that Hugging Face's malware scanning was an adequate control on the attack surface, and that the Studio, which was technically listed as being in beta, should be excluded from consideration" [10]. Pillar's reply was that neither argument deals with Studio executing repository code automatically [11]. Unsloth did not respond to Dark Reading's request for comment, sent through X [13].
Counting Studio, at least four AI development tools this year have had code-execution bugs centered on trust_remote_code [1]. Fogel told Dark Reading the recurrence points to a systemic gap in how machine learning tools handle executable model content [16]. Users treat model artifacts as data, but those artifacts can also supply code. In his account, a tool that silently enables the flag makes a consequential security decision on the user's behalf [16].
The Unsloth case differs in where the code ran. What stood out, he said, "is that the boundary was crossed during an action users reasonably understood as inspection" [17].
What to watch
- Whether Unsloth publishes an advisory or a CVE is assigned to the Studio flaw after the fact.
- Any Hugging Face repository found using config-time custom code against inspection features; Pillar says it has seen none so far.
- Other model-browsing or metadata tools found calling Transformers with trust_remote_code enabled by default.