Do you check auto_map before loading a model? Picking a model can execute code

iamjessew · reddit · 2026-10-06

A Reddit ML thread highlights an overlooked attack surface: automap in a repo's config. combined with trustremotecode can lead to arbitrary code execution. The trigger: an Unsloth Studio post showed that merely selecting a model in the UI — no weights loaded, no inference — ran Python from the repo, because a capability check called AutoConfig with trustremotecode on (fixed in 2026.6.9).

Key points:

If you pull models locally, this is an attack surface worth auditing.

Original post →

More from Safety

Safety channel →