GPU VulnDB

Database/AI/ML frameworks & serving

Unsloth Zoo: model config.json injects Python that runs via exec() when a model is loaded

CVSS 8.6CVE-2026-93348AI/ML frameworks & servingcurated

Impact

Any model artifact that a fine-tuning or inference job loads can execute arbitrary Python as the loading user. get_transformers_model_type() in hf_utils.py pulls model_type out of nested configs without an allowlist, so a newline in that value ends the generated import line and the rest is executed by exec() inside unsloth_compile_transformers(). On a GPU fleet this turns "pull a model from a hub and train it" into code execution inside the training container, with whatever the job holds: dataset mounts, hub and registry tokens, /dev/nvidia* and the node's network position. No user action beyond loading the model is required; the CVSS v4 vector marks passive user interaction only.

Who can reach it

Anyone who can get a model directory or hub repo loaded by an Unsloth job - a tenant submitting their own model, a shared internal model registry, or an untrusted public hub repo. No authentication to the cluster is needed if the fleet pulls models from public sources.

What to do

Upgrade Unsloth Zoo to 2026.8.14 or later (Unsloth 2026.8.20+). This is a Python package in the training image: rebuild or repin the image and restart the affected training/inference jobs. No node reboot or driver work. Until images are rebuilt, restrict Unsloth jobs to models from sources you control.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.