
Unsloth Studio 的已修补漏洞再次引发了对 AI 模型检查工具安全性的警示。该缺陷由 Dark Reading 披露,源于库中的 “trust_remote_code” 标志;启用后,允许执行模型仓库中嵌入的未经审查的 Python 代码。因此,恶意行为者可以嵌入负载,使其在常规模型检查期间自动运行,将本应良性的质量检查转变为完整的远程代码执行(RCE)向量。
该问题并非单纯的代码疏漏;它反映了推动快速 AI 创新的开源精神与对稳健供应链安全需求之间的深层矛盾。Unsloth Studio 是一款流行的轻量级微调框架,广泛用于加速大语言模型(LLM)的部署。平台允许开发者直接从公共仓库拉取模型权重及相关脚本,虽简化了实验流程,却也为对手提供了以合法模型为幌子注入恶意代码的入口。
复现该漏洞的安全研究人员演示了一个精心构造的模型可以下载额外的二进制文件、窃取环境变量,甚至在主机上建立持久化——这些都在用户察觉异常之前完成。漏洞已被迅速修补,维护者现在建议默认禁用 “trust_remote_code”,并通过加密签名验证模型来源。
对于政策制定者和合规官员而言,此次事件凸显了将现有软件供应链监管扩展至 AI 领域的紧迫性。例如,欧盟《AI 法案》已要求对高风险 AI 系统进行合规评估,但“高风险”的定义仍有争议。此类事件主张对包括模型训练和部署周边工具生态在内的更广泛范围进行解释。
行业参与者也必须重新评估内部控制。整合第三方模型库的组织应实施对可疑导入的自动扫描、强制最小权限执行环境,并保持模型来源的不可变审计日志。此外,AI 社区应加速采用诸如可信 AI 模型(TAM)框架等标准,该框架倡导对模型制品进行签名并实现可复现的构建流水线。
从长远来看,Unsloth 事件可能促使模型检查服务向更沙箱化的方向转变,或以内置 RCE 缓解措施的托管服务形式出现。虽然补丁恢复了即时安全,但也提醒我们,AI 创新的高速发展可能超前于安全最佳实践的制定。各方利益相关者——从开源维护者到监管机构——必须合作,在 AI 堆栈的每一层嵌入安全即设计的理念,否则未来的漏洞将不仅危及数据中心,更动摇支撑 AI 生态系统的根本信任。
图片:Innovalabs / Pixabay (https://pixabay.com/photos/software-developer-web-developer-6521720/)
As 2027 approaches, organizations face a critical juncture in AI adoption, demanding robust governance, stringent security, and clear value realization to navigate an impending era of heightened accountability and regulatory scrutiny.

New Linux implants disguise themselves as Asian email security products, highlighting the need for AI‑enhanced defenses.

A nonprofit has filed a lawsuit against OpenAI, asserting that the company cannot deflect blame for the Hugging Face hack by claiming 'an AI did it'. This case could redefine accountability for AI developers.

Enterprise AI agents wield privileged access, yet oversight lags behind human controls, creating a new insider‑threat vector for organizations.

评论 (1)
Your piece hits the nail on the head: the “trust_remote_code” convenience is a hidden liability that can undermine any AI‑first strategy if left unchecked. For enterprise leaders, the real question is how quickly they can embed zero‑trust gating and automated sandbox validation into their model‑ingestion pipelines before supply‑chain exploits become a routine operational risk.