<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Unsloth - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/unsloth/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:21:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/unsloth/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Unsloth Zoo via Model Configuration</title><link>https://feed.craftedsignal.io/briefs/2026-09-unsloth-rce/</link><pubDate>Mon, 28 Sep 2026 16:21:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-unsloth-rce/</guid><description>Unsloth Zoo and Unsloth are vulnerable to remote code execution due to improper input validation in the model-loading compile path, allowing arbitrary Python code execution via malicious config.json files.</description><content:encoded><![CDATA[<p>Unsloth Zoo versions 2025.9.9 before 2026.8.14 and Unsloth versions 2025.9.9 through 2026.8.19 contain a critical code injection vulnerability. The flaw exists within the <code>get_transformers_model_type()</code> function located in <code>hf_utils.py</code>, which is responsible for collecting <code>model_type</code> values from nested model configurations. The function fails to enforce a character allowlist, permitting newlines and arbitrary Python source code to pass through normalization.</p>
<p>An attacker can supply a malicious <code>config.json</code> file where the <code>model_type</code> field contains an injected newline character followed by arbitrary Python statements. When the model is loaded for training or inference, <code>unsloth_compile_transformers()</code> processes this configuration and passes the malicious input into an <code>exec()</code> call. This results in arbitrary code execution with the permissions of the user or service account performing the model load. This vulnerability impacts environments that load untrusted or externally sourced model configurations into Unsloth-based pipelines.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution in the context of the user running the Unsloth framework. This could lead to full system compromise, exfiltration of sensitive model data, or persistence on the server hosting the training or inference environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Upgrade Unsloth Zoo to version 2026.8.14 or later, and Unsloth to versions beyond 2026.8.19, to incorporate the necessary input sanitization.</li>
<li>Implement file integrity monitoring or scanning on model repositories to detect suspicious characters (e.g., newlines, <code>import</code>, <code>exec</code>, <code>eval</code>) within <code>config.json</code> files before they are processed by the training or inference pipeline.</li>
<li>Run model-loading processes in isolated, low-privilege containers or sandboxes to limit the impact of potential RCE in the <code>unsloth_compile_transformers()</code> function.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>