Skip to finding
important · RCE — ML

A malicious model configuration executes Python as the Unsloth training or inference user.

Affects

Unsloth and Unsloth Zoo, Python libraries used to load, fine-tune and serve machine-learning models.

When a workflow selects an attacker-controlled model, a newline-bearing model_type survives normalization, enters generated Python source and reaches exec().

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026