CVE-2026-93348: Unsloth Zoo Code Injection via model_type in config.json
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the gettransformersmodeltype() function in hfutils.py collects modeltype values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested modeltype value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unslothcompiletransformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Unsloth Zooto a version that resolves this vulnerability.Fixed in 2026.8.14