Product
Unsloth Zoo and Unsloth are vulnerable to remote code execution due to improper input validation in the model-loading compile path, allowing arbitrary Python code execution via malicious config.json files.