Unsloth Studio fixed flaw allowing arbitrary code execution
Unsloth Studio, a tool for AI model training, fixed a security bug that allowed code from remote model repositories to run on users' machines just by checking model metadata. Pillar Security found that the flaw could let attackers execute malicious code and access sensitive data. The bug was present in standard releases via PyPI and not limited to beta users. Studio's maintainers fixed the issue in June.
- Flaw allowed code to run during model metadata checks
- Bug affected standard Unsloth installs, not just beta
- Sensitive data like SSH keys could be exposed
- Unsloth's default setting enabled remote code execution
- Issue was fixed in June after disclosure
Sources covering this
More in AI
Google unveils Gemini 4 Argon for enterprise, cybersecurity use
Google has unveiled Gemini 4 Argon, its most advanced AI model to date.
DoorDash launches AI food ordering via Apple Messages
DoorDash just rolled out a waitlist for an AI-powered assistant that lets users in the U.S.
America.gov launches AI chatbot for government services
The White House has launched America.gov, a new website powered by Google's Gemini and xAI's Grok AI models.
Factory accuses ex-board advisor of sharing secrets with Cognition
Factory CEO Matan Grinberg claims he fired board advisor Chris Degnan for allegedly sharing confidential information with rival AI…