Shweta Sharma writes that Unsloth Studio, an AI-model-training tool in beta, contained a vulnerability where selecting a model could trigger arbitrary Python code execution on a user's machine. The issue stemmed from the application automatically enabling Hugging Face's `trust_remote_code` option during routine metadata checks, allowing specially crafted models to execute malicious code without downloading full weights or requiring inference.
- Pillar Security researcher Ariel Fogel discovered that reading only the `config.json` file was sufficient to trigger the exploit.
- A fix was released in version 2026.6.9 which prevents arbitrary model loading from Hugging Face and disables the automatic trust of remote code for local files.