CVE-2026-93348 Unsloth Zoo 代码注入漏洞
影响攻击者可通过恶意模型配置远程执行任意代码
Unsloth Zoo 在模型加载编译路径中存在代码注入漏洞。get_transformers_model_type() 从嵌套模型配置中收集 model_type 值时未做字符白名单校验,换行符与任意 Python 源码可绕过规范化处理。攻击者可在恶意模型 config.json 的嵌套 model_type 中嵌入换行,从而在 unsloth_compile_transformers() 的 exec() 中执行任意代码。
影响范围
Unsloth Zoo 2025.9.9 至 2026.8.14 之前版本,对应 Unsloth 2025.9.9 至 2026.8.19 版本。
漏洞详情
漏洞类型为代码注入(远程代码执行)。成因是 hf_utils.py 中 get_transformers_model_type() 未对 model_type 值实施字符白名单,换行符可终止生成的 import 语句。利用方式是构造恶意模型的 config.json,在嵌套 model_type 中注入换行及 Python 代码,加载模型训练或推理时经 exec() 执行。
利用条件与风险
利用前提是受害者加载攻击者提供的恶意模型;实战中加载不可信模型即可触发,风险较高。
修复建议
建议升级至 Unsloth Zoo 2026.8.14 及之后版本;临时缓解措施为仅加载可信来源的模型,暂无其他公开信息。
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model’s config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.