Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A now-patched vulnerability in Unsloth Studio allowed a malicious Hugging Face model repository to execute Python code when a user merely selected the model in the browser interface.

Unsloth fixed the issue in version 2026.6.9, and users running Studio should upgrade immediately. Unsloth is a popular open-source library used to fine-tune and quantize large language models. Its Studio component is a browser-based interface, listed as beta, that simplifies model selection, training, and related workflows.

The project has significant ecosystem reach: Hugging Face identifies Unsloth as the third-largest source of model derivatives on its Hub, behind Qwen and Google.

The flaw was discovered in Unsloth Studio’s backend model-inspection workflow. When an operator chose a Hugging Face model through the interface, Studio checked the model’s configuration before loading weights or starting inference however, the affected code path enabled trust_remote_code=True by default.

That setting is powerful but dangerous. Hugging Face model repositories can include custom Python files alongside model weights and configuration data.

Unsloth Studio RCE Flaw

A repository’s config.json can use the auto_map field to point Transformers components, such as AutoConfig, to those local Python files. If remote code is trusted, the Transformers library imports and executes the repository-provided module.

In vulnerable Studio releases, this happened during what appeared to be a harmless metadata inspection. An attacker could create a malicious model repository with a crafted config.json, convince a Studio user to select it, and cause code to run in the Studio backend process.

The victim did not need to load model weights, run training, begin inference, or explicitly approve remote code execution. The code would run with the permissions of the user operating Studio.

On AI development systems, that may expose Hugging Face tokens, cloud credentials, SSH keys, proprietary datasets, model artifacts, and training outputs.

Attackers could also tamper with local models, establish persistence, or use accessible credentials to reach other infrastructure. The vulnerable Studio logic was included in the standard unsloth Python package rather than a separate prerelease-only package.

Exploitation required the victim to run Studio and select an attacker-controlled model. However, the affected code could be installed through an ordinary pip install unsloth workflow.

Pillar Security reported the issue privately in early June 2026. Unsloth’s maintainers responded and released a fix on June 18. Researchers independently verified that version 2026.6.9 closes the vulnerable Hugging Face and local-directory model-loading paths.

The maintainers declined to publish an advisory because Studio was in beta, so no CVE has been assigned. Organizations should upgrade Unsloth Studio to version 2026.6.9 or later.

Security teams should also treat any use of trust_remote_code=True as execution of untrusted software, not as a routine model-loading option. Pin model repositories to known revisions, load them in isolated environments, and prevent access to long-lived credentials wherever possible.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code appeared first on Cyber Security News.