TechRadar News.
Technology

Remote Code Execution Bug in Unsloth Studio Triggered by Malicious Hugging Face Models

Remote Code Execution Bug in Unsloth Studio Triggered by Malicious Hugging Face Models

A team of security analysts has revealed a severe remote‑code‑execution flaw in Unsloth Studio, the widely‑used web interface for exploring and testing machine‑learning models. The defect permitted any model stored on Hugging Face to execute arbitrary Python code on a visitor’s system merely by being chosen in the Studio browser, without the need for the user to download or run the model themselves.

The problem originated in the way Unsloth Studio displayed model metadata. Upon clicking a model listing, the service retrieved a JSON manifest from Hugging Face and immediately evaluated any scripts contained within. An attacker could insert a malicious payload into that manifest, causing the Studio client to run the code in the user’s Python environment, which might compromise the machine or exfiltrate information.

Unsloth acted promptly, issuing version 2026.6.9 which cleanses incoming model descriptors and quarantines any executable material. The update also adds a tighter content‑security policy to the browser component, blocking automatic script runs. The firm has advised all users to upgrade without delay, emphasizing that the flaw could be exploited in any installation of earlier releases.

Although no widespread attacks have been disclosed, the attack surface is noteworthy as it reduces the effort required for adversaries to target data‑science groups and hobbyist programmers who routinely test models from public repositories. Specialists caution that comparable issues might appear in other AI tools that accept third‑party model metadata without adequate validation.

The finding highlights the increasing necessity for robust security practices within the fast‑growing AI landscape. Analysts advise firms to regard model repositories as potentially hostile, to sandbox model execution, and to maintain up‑to‑date AI‑related software. As AI use expands, incidents such as this demonstrate how classic software‑supply‑chain threats are now merging with machine‑learning pipelines.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related