> A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration)

I am sure they are paid well but they literally have RCE embedded in their infra. How is this acceptable?

You have an unnumbered amount of RCE's in your infra now, you just don't know they exist yet.

LLMs are very good at testing for and finding exploits, especially in unfiltered models with unlimited tokens.