Choosing a model in Unsloth Studio ran that model's code, and because the product was in beta there is no CVE to tell anyone
2026-10-05AI
Unsloth Studio checked a model's configuration with remote code trusted, so selecting an attacker-controlled model in the picker downloaded and executed Python from its Hugging Face repository. No weights loaded, no training started, no prompt to approve. Fixed in 2026.6.9, with no advisory and no identifier.