CyberHighReportedAccelerating
7.2
GitLab flags critical RCE in AI Gateway, urges immediate patching
BleepingComputerLO·1 day ago
A patched vulnerability in Unsloth Studio, an AI model inspection tool, allows malicious models to execute arbitrary Python code via the trust_remote_code setting. The flaw enables code execution during routine model inspection, posing a supply-chain risk to AI developers. The patch is available, but the incident highlights systemic risks in AI model trust boundaries.