SEPTEMBER 30, 2026
Subscribe
Global Press Media · World Report
Technology

Critical Remote Code Execution Bug Found in Unsloth Studio via Malicious Hugging Face Models

Critical Remote Code Execution Bug Found in Unsloth Studio via Malicious Hugging Face Models

A team of security analysts reported a severe remote‑code‑execution flaw in Unsloth Studio, the widely‑used web interface for exploring and evaluating machine‑learning models. The defect permitted any model stored on Hugging Face to execute arbitrary Python code on a visitor’s computer merely by being chosen in the Studio’s browser, with no need for the user to download or run the model themselves.

The problem originated in the way Unsloth Studio displayed model metadata. Upon clicking a model listing, the service retrieved a JSON manifest from Hugging Face and immediately evaluated any scripts contained within. An attacker could insert a malicious payload into that manifest, causing the Studio client to run the code in the user’s Python environment, which could jeopardize the system or exfiltrate information.

Unsloth acted swiftly, issuing version 2026.6.9 which cleanses incoming model descriptors and quarantines any executable material. The update also adds a tighter content‑security policy to the browser component, blocking automatic script runs. The vendor has advised all users to apply the upgrade without delay, emphasizing that the flaw could be exploited in any setup using earlier releases.

Although no widespread incidents have surfaced publicly, the attack surface is noteworthy as it reduces the effort required for malicious actors to target data‑science groups and hobbyist programmers who regularly test models from public repositories. Specialists caution that comparable vulnerabilities might appear in other AI tools that accept third‑party model metadata without adequate verification.

This finding highlights the increasing demand for robust security measures within the fast‑growing AI landscape. Advisors suggest that firms regard model repositories as potentially hostile, use sandbox environments for model runs, and maintain all AI‑related applications with the latest patches. As AI uptake speeds up, cases such as this demonstrate how classic software‑supply‑chain threats are now converging with machine‑learning pipelines.

Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related