Unsloth Zoo 在 2025.9.9 至 2026.8.14 之前版本(即 Unsloth 2025.9.9 至 2026.8.19 版本中实现的组件)存在代码注入漏洞。该漏洞位于模型加载的编译路径中, 文件中的 函数从嵌套的模型配置中收集 值时,未对字符进行白名单校验,导致换行符和任意 Python 源代码在规范化处理后仍能保留。 攻击者可在恶意模型的 文件中,于嵌套的 字段中嵌入一个换行符,从而终止生成的 import 语句,并通过 中的 执行任意 Python 代码。当该模型被加载用于训练或推理时,攻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| unslothai | unsloth-zoo | 2025.9.9 ~ 2026.8.14 | - |
|
| unslothai | unsloth | 2025.9.9 ~ 2026.8.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet