See how unsloth compares to other vendors in security performance
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the gettransformersmodeltype() function in hfutils.py collects modeltype values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested modeltype value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unslothcompiletransformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.