Studio Read config.json. Transformers Ran the File

Pillar showed Unsloth Studio executing Hugging Face Python on a metadata check. Version 2026.6.9 closed it. trust_remote_code=True is still in other pipelines.

Dark Reading published Ariel Fogel’s write-up of a flaw in Unsloth Studio: pick a malicious Hugging Face model, and the UI executed Python from that repo. The backend did not load weights. Reading config.json was enough. InfoWorld dated the fix to version 2026.6.9 and said Pillar retested both the Hugging Face path and a local-directory path. GBHackers named the Transformers hook: an auto_map field pointing at custom Python files in the repo, with trust_remote_code=True on during the inspection.

This is not the Langflow exec from September. It is the same class of lesson in a fine-tuning UI: a convenience flag that turns a catalog click into import. We already noted that Transformers will load a GGUF. Loading is a different verb from inspecting. Studio collapsed them.

The click was a metadata check

Fogel’s line, as Dark Reading quotes it: the code ran from nothing more than a metadata check. The act of inspecting a model was enough. That sentence should be on the wall of every team that built a “model zoo” dropdown. Dropdowns feel like reading. Transformers, with remote code on, can make them running.

GBHackers describes the attacker’s write: put auto_map in config.json so Transformers fetches custom Python from the repository. You do not need a GPU for that. You need a UI that asks for capabilities before it asks whether you trust the author. Studio was that UI.

Dark Reading says Pillar has seen no evidence of real-world exploitation of this particular mechanism, while noting other campaigns have used malicious models on Hugging Face. Absence of a known victim is not a reason to stay on the old build. It is a reason you still have time to patch before the next copied PoC.

InfoWorld is careful on blame: this is not a Hugging Face vulnerability. It is how Unsloth used trust_remote_code. Hugging Face’s malware scanning, in Unsloth’s pushback as Pillar tells it, was treated as a control. Pillar’s counter: those protections are mostly blocklists, and the PoC was not flagged when scanned, but could have fetched a second-stage payload only when processed by Unsloth. If your threat model is “HF already scanned it,” this week’s articles are the rebuttal.

What 2026.6.9 actually changed

InfoWorld: in 2026.6.9, Studio no longer enables arbitrary model loading directly from Hugging Face and does not trust remote code from local model files. Pillar independently retested and confirmed both attack paths closed. GBHackers repeats the upgrade instruction and adds the boring one: examine every instance of trust_remote_code=True in AI development pipelines, even if you never open Studio.

That second sentence is the Python article. Unsloth core users who only ever call the library still got the “upgrade anyway” advice from Pillar, per InfoWorld. UI bugs leak into shared loaders. If your production job never launches a browser and still imports the same stack, you are in the blast radius until you read the changelog.

Dark Reading’s timeline: Pillar reported in early June, Unsloth addressed it later that month in 2026.6.9. Fast, as these things go. The dispute, as Fogel’s post claimed, was whether Hugging Face scanning was adequate and whether Studio, listed as beta, should be excluded from consideration. Beta is not a permission to execute repo Python on hover. If you ship a beta next to a model picker used by people with cloud credentials, you own the picker.

Pin the version. Do not pin “latest.” 2026.6.9 is the floor named in these pieces. If your lockfile still says an earlier 2026.6, you are arguing with a dated inspect path.

Why the flag exists, and why defaults lie

InfoWorld lists legitimate models that need custom code: IBM Granite Speech and Vision, DeepSeek-OCR, ChatGLM, earlier Qwen releases. trust_remote_code is not an always-wrong switch. It is an install of unknown Python that happens to live beside weights. Some models will not load without it. That is a documentation problem and a consent problem. It is not a reason to turn it on for a capabilities check that only needed config.json.

Pillar’s first recommendation, per InfoWorld, was pinning trust_remote_code=False on the model-checking path because that path only needed declarative information. Unsloth’s eventual fix went further than flipping the flag. Read that as: the check path should never have been a load path. If your own code calls from_pretrained to print architectures, you probably copied the same shortcut.

The default is the bug. A researcher who knows they are loading ChatGLM can pass True and accept the risk. A dropdown that passes True because the helper function always did is how a catalog becomes RCE. Write the kwarg at the call site. Do not inherit it from a utility named get_model_info.

If you wrap Transformers behind an internal API, make the default False and require a second argument, like a repo revision pin, before True is legal. If you cannot name the revision, you cannot name the code. Ruff’s S rules will not read that PR for you. They might catch a hardcoded secret. They will not catch a loader.

Treat custom-code repos like untrusted software

GBHackers’ close is the policy version: model repositories that require remote code should be treated as untrusted software, loaded only with explicit user approval, pinned to known revisions, and isolated from credentials and production systems. That is not metaphor. It is pip install with extra steps and a GPU bill.

Practical floor for a Python shop this week:

  • Grep trust_remote_code in every repo you own. Count True. Each True needs a comment with a revision SHA and a person.
  • Stop using “inspect” helpers that call from_pretrained. Parse config.json as JSON.
  • If Studio is installed anywhere, upgrade to 2026.6.9 or later. If it is not in the SBOM because “someone’s laptop,” it is still in the SBOM.
  • Do not pass cloud keys into the same process that loads community models. The PoC in these stories did not need weights. It needed a process.

Fogel, in InfoWorld, warned that time-to-exploit keeps shrinking because automated repo scanning, agentic exploitation, and supply-chain campaigns can weaponize a benign-looking auto_map module faster than before. You do not need to buy that as a trend forecast. You need to notice that the trigger was a UI select, which is exactly what agents and interns both do.

Hugging Face warnings on models that ship custom code are a label. Labels fail when the loader ignores them. Studio’s inspection path ignored the spirit of the label by never asking. Your CLI can fail the same way with a default kwarg.

What this is not

It is not a reason to stop using Unsloth for fine-tunes you already trust. The maintainers shipped a fix the same month as the report. It is not a reason to claim Hugging Face is “hacked.” InfoWorld said the opposite. It is not a Langflow clone with the serial numbers filed off. Different product, same Python footgun: execute code because a file in a model repo said so.

It is also not a substitute for reading Transformers docs on auto_map. If you maintain an internal zoo, add a CI check that fails when config.json contains auto_map unless a allowlist file names that repo and SHA. That is a twenty-line test. It will catch the next dropdown.

Do not paste exploit steps into an internal wiki “for awareness.” Paste the version floor, the grep, and the JSON-only inspect rule. Awareness without a loader change is a lunch talk.

Notebooks, agents, and the other loader

The grep in the next section will miss Colab, VS Code notebooks, and the one-off ipython history on a GPU box. Those are where from_pretrained(..., trust_remote_code=True) gets copied from a model card and never reviewed. Search *.ipynb as well. If your team fine-tunes from a shared notebook server, treat that server like Studio: same process, same credentials, same default.

Agents make this worse without a new CVE. Fogel’s InfoWorld warning about agentic exploitation is about shrinking time-to-exploit, not a named Unsloth worm. An agent that “tries candidate models from the hub” is a model picker. If it uses Transformers with remote code on, it is Studio without a GUI. Point the agent at a JSON allowlist. Do not point it at “whatever is trending.”

Local directories were the second path Pillar retested. InfoWorld says 2026.6.9 also stopped trusting remote code from local model files. People copy a hub repo to disk and think they went offline. They brought auto_map with them. A folder named ./weights/qwen-finetune is still software. Scan it like a dependency, or parse config as text.

DeepSeek-OCR, Granite Speech, ChatGLM, and older Qwen, the examples InfoWorld used, are the legitimate exceptions. Put those names in an allowlist file with SHAs. When someone adds a fifth, they add a line, not a default. If a new architecture cannot load without custom code and is not on the list, that is a change request, not a True you paste to unblock a demo.

If Unsloth disputed Studio’s beta status, copy that argument into your own bug tracker the next time someone ships an internal “playground.” Playgrounds get used. Used playgrounds get credentials. Credentials plus from_pretrained is the bug even when the README says experimental.

The checklist you can run today

  1. rg "trust_remote_code" -g "*.py" on every training box and CI image.
  2. Upgrade Unsloth / Studio to 2026.6.9+ where it exists.
  3. Replace capability probes with json.load on config.json.
  4. Require a revision pin for any model that still needs remote code.
  5. Keep secrets out of that process.

If step 1 returns nothing, you are either clean or your loaders live in a notebook nobody grepped. Search the notebooks. Studio users who never committed the flag still had it on in the UI backend. Defaults hide.

Add *.ipynb to the same ripgrep. Add Docker images that bake Unsloth. Add the one research fork that vendors Transformers. The inspect path was a convenience function. Convenience functions get copied. If three internal wrappers all default True, patching Studio does not patch you.

The news is a patched beta UI. The practice is older than the CVE-shaped headlines. A metadata read should read metadata. The moment it imports, you are installing software from whoever won the filename. Pin it, or do not click it.

Spread The Article

Share this guide

Send this article to your network or keep a copy of the direct link.

X Facebook LinkedIn Reddit Telegram

Discussion

Leave a comment

No comments yet

Be the first to start the conversation.