important · RCE — ML
A malicious model configuration executes Python as the Unsloth training or inference user.
Affects
Unsloth and Unsloth Zoo, Python libraries used to load, fine-tune and serve machine-learning models.
When a workflow selects an attacker-controlled model, a newline-bearing model_type survives normalization, enters generated Python source and reaches exec().
Detail and 4 sources
Sources
Code / PoCStop building imports from a config-supplied model_type by danielhanchen · Pull Request #1083 · unslothai/unsloth-zoo · GitHubCode / PoCStop config-supplied values reaching exec, eval and getattr sinks by danielhanchen · Pull Request #1108 · unslothai/unsloth-zoo · GitHubPatchUpdate pyproject.toml · unslothai/unsloth@92ee020 · GitHubVendorUnsloth Zoo Code Injection via model_type in config.json | Advisories | VulnCheck