Skip to content
cve — cve-2026-93348

grep -rl "CVE-2026-93348" ./articles

CVE-2026-93348

Unsloth Studio checked a model's configuration with remote code trusted, so selecting an attacker-controlled model in the picker downloaded and executed Python from its Hugging Face repository. No weights loaded, no training started, no prompt to approve. Fixed in 2026.6.9, with no advisory and no identifier.

1 article — 2026-10-05

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered