High priorityDisclosed

Advisory · CVE-2026-93348

A malicious model config can inject code into Unsloth's compile path

Unsloth Zoo before 2026.8.14 builds a Python import statement from model_type values without an allowlist, so a crafted config.json newline injects arbitrary Python that runs when the model is loaded.

Vendor
Unsloth
Product
unsloth-zoo
Identifier / CWE
CVE-2026-93348
CWE-94
Action timing
Immediate
ELI5

Explain it like I’m five

Unsloth assembles an import line from text inside a model's config file. A malicious model can hide a line break in that text so the rest becomes attacker-written code, which Unsloth then runs.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Malicious model config

    An attacker crafts a model's config.json with a newline embedded in a nested model_type value.

  2. 02Unsafe normalization

    get_transformers_model_type() in hf_utils.py collects model_type values from nested configs without enforcing a character allowlist, so the newline and trailing Python source survive normalization.

  3. 03Import statement terminated

    The injected newline ends the generated import statement early, turning the attacker-supplied text into executable Python.

  4. 04Code execution at load

    unsloth_compile_transformers() passes the result to exec(), running the attacker's code as the loading user when the model is loaded for training or inference.

What happened

Unsloth Zoo versions from 2025.9.9 up to, but not including, 2026.8.14 contain a code injection vulnerability in the model-loading compile path. The get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, so newlines and arbitrary Python source survive normalization. An attacker can embed a newline in a nested model_type value inside a malicious model’s config.json to terminate the generated import statement, and unsloth_compile_transformers() then executes the injected Python via exec(). This achieves remote code execution as the loading user when the model is loaded for training or inference. The unsloth package itself is affected from 2025.9.9 up to, but not including, 2026.8.20.

What to do

  1. Inventory training, inference, and evaluation environments that use Unsloth or Unsloth Zoo.
  2. Upgrade to unsloth-zoo 2026.8.14 or later and unsloth 2026.8.20 or later.
  3. Treat models from untrusted sources as untrusted code: load them only in sandboxed environments with no access to credentials or production networks.
  4. Review model-loading logs and process histories for models loaded from unfamiliar sources.
  5. Determine which credentials, keys, and datasets were reachable from any environment that loaded an untrusted model, and rotate them if compromise cannot be excluded.

Management note

This turns a common workflow, loading a community model, into code execution on the machine that trains or serves it. Patch, and pair that with a policy that untrusted model artifacts never load on machines with production access.