Unsloth’s model picker had a code-execution problem

Summary

The AI model-training tool Unsloth has a critical vulnerability where selecting a model could trigger arbitrary code execution on a developer's system. This was discovered by Pillar Security, who found that a specially crafted model could cause Unsloth Studio to download and execute malicious Python code, potentially exposing sensitive data.

IFF Assessment

FOE

The vulnerability allows for arbitrary code execution, which is a severe security risk for defenders as it can lead to system compromise and data theft.

Severity

9.0 Critical (AI Estimated)

The vulnerability allows for arbitrary code execution (high impact) through a simple metadata check (low attack complexity) and without requiring user interaction beyond selecting a model. This grants attackers significant control over the victim's system.

Defender Context

This incident highlights the risks associated with AI development tools and the supply chain of AI models. Defenders should be cautious about the source of AI models and the security posture of the tools used for training and development, especially those that execute code from external sources.

Read Full Story →