A patched Unsloth Studio flaw allowed malicious Hugging Face models to execute Python code when selected in the browser.