CVE-2026-93348 Details
Description
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
A code injection vulnerability has been identified in Unsloth Zoo versions 2025.9.9 prior to 2026.8.14. This vulnerability arises in the model-loading compile path, where the function get_transformers_model_type() in hf_utils.py retrieves model_type values from nested model configurations without applying a character allowlist. This oversight allows newlines and arbitrary Python code to bypass normalization. Attackers can exploit this by inserting a newline into a nested model_type value within a malicious model's config.json, effectively terminating the import statement and executing arbitrary Python code via exec() in the function unsloth_compile_transformers(). This exploitation leads to remote code execution as the user loading the model, particularly during training or inference.
Users can upgrade to Unsloth Zoo versions 2026.8.15 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/unslothai/unsloth/commit/92ee0207a38ebc8af1a0e678aa92d7e7d901ea0d | [email protected] | Source CodeVendor |
| https://github.com/unslothai/unsloth-zoo/pull/1083 | [email protected] | Issue TrackingVendor |
| https://github.com/unslothai/unsloth-zoo/pull/1108 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/unsloth-zoo-code-injection-via-model-type-in-config-json | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Unsloth Zoo | >= 2025.9.9, < 2026.8.14 (semver) |
CPE
Remediation
| |
| Unsloth | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion