Remote Code Execution in Unsloth Zoo via Model Configuration
Unsloth Zoo and Unsloth are vulnerable to remote code execution due to improper input validation in the model-loading compile path, allowing arbitrary Python code execution via malicious config.json files.
CVE search metadata
CVE search record: CVE-2026-93348. Severity: high. CVSS: 8.1. KEV: no. Product: Unsloth Zoo (2025.9.9-2026.8.13), Unsloth (2025.9.9-2026.8.19). Brief: Remote Code Execution in Unsloth Zoo via Model Configuration. Brief link: https://feed.craftedsignal.io/briefs/2026-09-unsloth-rce/
Unsloth Zoo versions 2025.9.9 before 2026.8.14 and Unsloth versions 2025.9.9 through 2026.8.19 contain a critical code injection vulnerability. The flaw exists within the get_transformers_model_type() function located in hf_utils.py, which is responsible for collecting model_type values from nested model configurations. The function fails to enforce a character allowlist, permitting newlines and arbitrary Python source code to pass through normalization.
An attacker can supply a malicious config.json file where the model_type field contains an injected newline character followed by arbitrary Python statements. When the model is loaded for training or inference, unsloth_compile_transformers() processes this configuration and passes the malicious input into an exec() call. This results in arbitrary code execution with the permissions of the user or service account performing the model load. This vulnerability impacts environments that load untrusted or externally sourced model configurations into Unsloth-based pipelines.
Impact
Successful exploitation allows for arbitrary code execution in the context of the user running the Unsloth framework. This could lead to full system compromise, exfiltration of sensitive model data, or persistence on the server hosting the training or inference environment.
Recommendation
Prioritized, concrete actions for detection engineering teams:
- Upgrade Unsloth Zoo to version 2026.8.14 or later, and Unsloth to versions beyond 2026.8.19, to incorporate the necessary input sanitization.
- Implement file integrity monitoring or scanning on model repositories to detect suspicious characters (e.g., newlines,
import,exec,eval) withinconfig.jsonfiles before they are processed by the training or inference pipeline. - Run model-loading processes in isolated, low-privilege containers or sandboxes to limit the impact of potential RCE in the
unsloth_compile_transformers()function.
Immediate actions
Upgrade Unsloth Zoo to 2026.8.14 or later
Mitigations
Enforce strict schema validation on all incoming model config.json files
CVE-2026-93348