⌁AI·CYBER·BRIEF▌

#CVE-2026-93348

Vulnerabilities8 min read

Two Unsloth flaws let a model's config file run code — one needs no trust_remote_code

A Pillar Security researcher found two ways a Hugging Face model's config.json could run code on machines using Unsloth. Both are fixed; only one got a CVE.

Hugging FaceCVE-2026-93348Unsloth