InstructLab hardcodes trust_remote_code=True in linux_train.py for all HuggingFace from_pretrained() calls. This enables arbitrary Python code execution from malicious model repositories on HuggingFace Hub. Attacker needs only a free HuggingFace account; victim runs ilab train/download/generate with the malicious model name. Upstream notification: security-reporting bounced for external senders. Filed via Red Hat.