{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/unsloth/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-93348"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Unsloth Zoo (2025.9.9-2026.8.13)","Unsloth (2025.9.9-2026.8.19)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Unsloth"],"content_html":"\u003cp\u003eUnsloth Zoo versions 2025.9.9 before 2026.8.14 and Unsloth versions 2025.9.9 through 2026.8.19 contain a critical code injection vulnerability. The flaw exists within the \u003ccode\u003eget_transformers_model_type()\u003c/code\u003e function located in \u003ccode\u003ehf_utils.py\u003c/code\u003e, which is responsible for collecting \u003ccode\u003emodel_type\u003c/code\u003e values from nested model configurations. The function fails to enforce a character allowlist, permitting newlines and arbitrary Python source code to pass through normalization.\u003c/p\u003e\n\u003cp\u003eAn attacker can supply a malicious \u003ccode\u003econfig.json\u003c/code\u003e file where the \u003ccode\u003emodel_type\u003c/code\u003e field contains an injected newline character followed by arbitrary Python statements. When the model is loaded for training or inference, \u003ccode\u003eunsloth_compile_transformers()\u003c/code\u003e processes this configuration and passes the malicious input into an \u003ccode\u003eexec()\u003c/code\u003e call. This results in arbitrary code execution with the permissions of the user or service account performing the model load. This vulnerability impacts environments that load untrusted or externally sourced model configurations into Unsloth-based pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the user running the Unsloth framework. This could lead to full system compromise, exfiltration of sensitive model data, or persistence on the server hosting the training or inference environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Unsloth Zoo to version 2026.8.14 or later, and Unsloth to versions beyond 2026.8.19, to incorporate the necessary input sanitization.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring or scanning on model repositories to detect suspicious characters (e.g., newlines, \u003ccode\u003eimport\u003c/code\u003e, \u003ccode\u003eexec\u003c/code\u003e, \u003ccode\u003eeval\u003c/code\u003e) within \u003ccode\u003econfig.json\u003c/code\u003e files before they are processed by the training or inference pipeline.\u003c/li\u003e\n\u003cli\u003eRun model-loading processes in isolated, low-privilege containers or sandboxes to limit the impact of potential RCE in the \u003ccode\u003eunsloth_compile_transformers()\u003c/code\u003e function.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T16:21:11Z","date_published":"2026-09-28T16:21:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-unsloth-rce/","summary":"Unsloth Zoo and Unsloth are vulnerable to remote code execution due to improper input validation in the model-loading compile path, allowing arbitrary Python code execution via malicious config.json files.","title":"Remote Code Execution in Unsloth Zoo via Model Configuration","url":"https://feed.craftedsignal.io/briefs/2026-09-unsloth-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Unsloth","version":"https://jsonfeed.org/version/1.1"}