Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Unsloth Studio flaw could let a poisoned AI model run its code just by being inspected

Selecting a model in the fine-tuning tool's web interface could execute Python shipped in the model's repository; the fix is in version 2026.6.9, but no CVE was assigned.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Pillar Security says Unsloth Studio ran code from a model's repository as soon as a user selected that model.
  • 2Versions up to 2026.5.10 were affected; Pillar verified the fix in 2026.6.9, and maintainers declined to publish an advisory.
  • 3Pillar's test model was not flagged by Hugging Face's scanner, so hub scanning alone is not a sufficient control.

The news

An Unsloth Studio flaw could let a malicious AI model run its own code on a user's machine the moment the user selected it for inspection, Pillar Security said in a September 29 write-up. The fix shipped in Unsloth version 2026.6.9.

Unsloth is an open-source library for fine-tuning AI models, which means adapting a pretrained model with new data, and for quantizing them, which shrinks them to run on cheaper hardware. Pillar called it one of the most popular libraries of its kind and said Hugging Face ranks it as the third-largest source of model derivatives on its Hub, behind Qwen and Google (GOOGL). Studio is Unsloth's browser-based interface. It is labeled beta but ships in the standard package that developers install.

According to Pillar, the function Studio used to read a model's settings turned on a Hugging Face Transformers option called trust_remote_code by default. A model's config.json file can point to Python files stored alongside it, and with that option on, Transformers imports and runs them. Pillar said the backend never loaded model weights or ran inference: "the act of inspecting a model was enough to run its code." The fix closed the path for both Hugging Face downloads and local model folders.

The code ran with the user's permissions. In an enterprise AI development environment, Pillar said, that could expose proprietary training data, model files, and any Hugging Face tokens, SSH keys or cloud credentials the process could reach. An attacker could also tamper with model weights and outputs or move to other systems from GPU-equipped hosts. Pillar said its proof-of-concept model was not flagged by Hugging Face's malware scanner.

Pillar reported the issue privately in early June 2026. Maintainers acknowledged it on June 16, and Pillar verified the fix in version 2026.6.9 in late June; versions up to 2026.5.10 were affected. Pillar said the maintainers disputed its assessment, arguing that Hugging Face's malware scanning was an adequate control and that Studio's beta status set it apart, then declined to publish an advisory, so no CVE identifier was assigned.

Unsloth's own fix, a code change titled Harden model fetching in its GitHub repository, removes the blanket switch that enabled custom code. It adds a review step that scans a model's custom code and blocks high- and critical-severity findings unless a user approves that specific version, and it uses Hugging Face's scan results to block flagged files. Pillar's write-up describes a proof-of-concept and does not report attacks using the flaw.

The numbers

Affected versions
Unsloth up to 2026.5.10
Fixed version
2026.6.9 or later
CVE identifier
None assigned
Unsloth's rank as a source of model derivatives on Hugging Face (per Pillar)
Third

Why CEOs should care

For CISOs and heads of AI platforms, the lesson is that a model repository can be software, not just data. Treat model intake the way you treat third-party code: approved sources, pinned versions and review before anything runs. Pillar recommends upgrading Unsloth Studio to 2026.6.9 or later, auditing every place in your stack where trust_remote_code is switched on, pinning model downloads to a specific commit and preferring the safetensors file format, which stores weights without executable code.

Do not lean on the model hub to catch this. Pillar's test model passed Hugging Face's scanner, and the maintainers cited that scanning as a sufficient safeguard. Machines used to browse and fine-tune models often hold cloud keys and access tokens, so keep long-lived credentials off them and inspect unfamiliar models in isolated environments.

For buyers and procurement teams, the missing CVE matters. Vulnerability scanners that key on CVE identifiers will not flag old Unsloth installs, so asset owners must check versions directly. Ask AI tooling vendors how they disclose security fixes and whether features labeled beta but shipped in production packages fall under their security policy.

The bigger picture

Pillar placed the Unsloth issue in a pattern, citing similar 2026 flaws in LMDeploy, vLLM and InstructLab tracked as CVE-2026-46432, CVE-2026-4944 and CVE-2026-6859. Remote code options exist so new model designs can ship custom code, but they turn every downloaded model into a possible entry point. Pillar's recommended rule is that a repository's code should run only when a user knowingly opts in for that action, never as a side effect of something else.

What’s next

Watch whether Unsloth publishes a formal advisory, whether other fine-tuning and serving tools change their defaults for remote code, and whether Hugging Face updates its scanning to catch code referenced from model configuration files.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

UnslothPillar SecurityHugging FaceAI supply chain

Earlier coverage of Hugging Face

All Hugging Face coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.