Code Injection Vulnerability in Unsloth Zoo from Unsloth AI
CVE-2026-93348

8.6HIGH

Key Information:

Vendor

Unslothai

Vendor
CVE Published:
28 September 2026

What is CVE-2026-93348?

The Unsloth Zoo has a vulnerability in its handling of model configurations, specifically in the get_transformers_model_type() function. This flaw arises from a lack of proper character validation on model_type values extracted from nested configurations, which can permit the execution of arbitrary Python code. When an attacker crafts a malicious model's config.json file to include a newline character in the model_type value, they can disrupt the import statement during model loading processes. This allows for remote code execution on the system where the model is being trained or analyzed, posing significant security risks to users.

Affected Version(s)

unsloth 2025.9.9 < 2026.8.20

unsloth-zoo 2025.9.9 < 2026.8.14

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ariel Fogel (afogel) of Pillar Security
.