Error database

ValueError: requires you to execute the configuration file (trust_remote_code)

The model's architecture is defined by Python code inside its repo, not inside transformers — and running that code needs your explicit consent. Review the repo, then pass trust_remote_code=True with a pinned revision.

The message you saw
ValueError: requires you to execute the configuration file (trust_remote_code)

By Updated

The error

Output
ValueError: Loading ExampleOrg/custom-model requires you to execute the configuration file in that repo on your local machine. Make sure you have read the code there to avoid malicious use, then set the option `trust_remote_code=True` to remove this error.

What it means

Most models load through architecture classes that live inside the transformers library itself — reviewed, versioned, safe. Some repos instead ship their own modeling code as Python files next to the weights. Loading such a model means downloading that code and executing it on your machine, with all your permissions. Transformers refuses to do that silently. The error is a consent form.

Why it happens

Model authors release architectures faster than libraries can absorb them, so the repo carries the class definitions itself. Nothing is wrong — but the security posture changes completely. A pickle file can hide code; here the repo openly is code. Anyone able to push to that repo can change what runs on your machine at the next download.

How to fix it

1. Look at the code before trusting it. On the model page, open the repo's Files tab and skim the .py files — modeling_*.py and configuration_*.py. You are checking for anything beyond model definitions: network calls, file access, subprocess use. For models from major organisations this is quick reassurance; for unknown uploaders it is the whole point.

2. Then opt in explicitly.

python
from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained(
    "ExampleOrg/custom-model",
    trust_remote_code=True,
    revision="a1b2c3d",              # pin an exact commit
)
tok = AutoTokenizer.from_pretrained(
    "ExampleOrg/custom-model", trust_remote_code=True, revision="a1b2c3d"
)

3. Pin revision to a commit hash. This is the part most people skip. Without it, you re-download whatever the repo contains at each run — the code you reviewed today can be silently replaced tomorrow. With a pinned commit, what runs is exactly what you reviewed. Take the hash from the repo's commit history.

4. Prefer natively supported models when the choice exists. Popular architectures get merged into transformers over time. If a newer transformers release supports the model natively, upgrading removes the custom-code requirement entirely — check the model card for a minimum version note.

5. In shared or automated pipelines, treat this flag as a code-review event. trust_remote_code=True in a service that loads arbitrary user-specified models is an execution vulnerability, not a convenience.

How to prevent it

Keep a short allowlist of repos your project trusts with remote code, each with its pinned revision, and load only from it. Revisit when upgrading transformers — models graduating to native support let you drop entries from the list.