VulnerabilitiesSep 29, 2026
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Unsloth Studio vulnerability allows arbitrary code execution via malicious AI models.
Summary
A vulnerability in Unsloth Studio, a tool for optimizing AI models, has been patched. The flaw, identified as CVE-2024-41104, allowed malicious AI models to execute arbitrary Python code on a user's system when the `trust_remote_code` setting was enabled during model inspection. This could have turned a routine model check into a security risk.
Indicators of Compromise
- cve — CVE-2024-41104
Entities
Unsloth Studio (product)Python (technology)