Database/AI/ML frameworks & serving
Unsloth Zoo: model config.json injects Python that runs via exec() when a model is loaded
Impact
Any model artifact that a fine-tuning or inference job loads can execute arbitrary Python as the loading user. get_transformers_model_type() in hf_utils.py pulls model_type out of nested configs without an allowlist, so a newline in that value ends the generated import line and the rest is executed by exec() inside unsloth_compile_transformers(). On a GPU fleet this turns "pull a model from a hub and train it" into code execution inside the training container, with whatever the job holds: dataset mounts, hub and registry tokens, /dev/nvidia* and the node's network position. No user action beyond loading the model is required; the CVSS v4 vector marks passive user interaction only.
Who can reach it
Anyone who can get a model directory or hub repo loaded by an Unsloth job - a tenant submitting their own model, a shared internal model registry, or an untrusted public hub repo. No authentication to the cluster is needed if the fleet pulls models from public sources.
What to do
Upgrade Unsloth Zoo to 2026.8.14 or later (Unsloth 2026.8.20+). This is a Python package in the training image: rebuild or repin the image and restart the affected training/inference jobs. No node reboot or driver work. Until images are rebuilt, restrict Unsloth jobs to models from sources you control.
References
Related entries
- Qdrant (`/logger`): Append to arbitrary files via the logger endpointCVE-2026-25628 · Qdrant (`/logger`)High
- llama.cpp llama-server: crafted sampler parameter triggers out-of-bounds read and unauthenticated crashCVE-2026-43628 · llama.cpp llama-server (DRY sampler, /v1/completions and /v1/chat/completions)High
- NVIDIA OpenShell Sandbox: path traversal bypasses L7 REST network policy, exposing blocked endpointsCVE-2026-65092 · NVIDIA OpenShell Sandbox for Linux (L7 REST network policy enforcement)High
- Darknet: integer overflow in convolutional layer sizing yields a heap overflow from a crafted .cfgCVE-2026-72852 · hank-ai/darknet convolutional layer (.cfg model definition parsing)High
- vLLM: remote processor code executes even when trust_remote_code is falseCVE-2026-90553 · vLLM (LlavaOnevision2 processor loader)High
- skops (`Card.get_model`): Model card loading has no trusted-types checkCVE-2025-54886 · skops (`Card.get_model`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.