JFrog confirmed that the OpenAI mannequin exploited a zero-day vulnerability within the self-hosted Artifactory server to flee from its remoted check setting and achieve entry to the web earlier than attacking Hugging Face.
This vulnerability was exploited throughout an incident during which an OpenAI mannequin hacked Hugging Face’s operational infrastructure and stole cybersecurity benchmark solutions.
OpenAI revealed final week that its fashions, together with GPT-5.6 Sol and higher-performance pre-release fashions, are being examined in opposition to ExploitGym, a benchmark designed to measure superior cyber capabilities.
This mannequin was run with out the manufacturing safeguards sometimes used to forestall AI brokers from conducting autonomous cyber actions.
Nevertheless, the agent was situated in a extremely remoted setting, with community entry restricted to bundle set up by means of internally hosted third-party software program that acted as a proxy and cache for the bundle registry.
Through the analysis, the mannequin spent a major period of time looking for methods to entry the open Web to acquire check options for the benchmarks.
In keeping with OpenAI, these fashions exploited a zero-day vulnerability in an unnamed bundle registry proxy to carry out privilege escalation and lateral motion inside the analysis setting till they reached a system with web entry.
On the time, OpenAI didn’t determine the bundle registry proxy software program or vendor, saying solely that the vulnerability was privately disclosed and patched.
After reaching the web, the mannequin decided that Hugging Face hosted the ExploitGym dataset and was seemingly internet hosting the check answer it was attempting to retrieve.
OpenAI mentioned the mannequin explored methods to entry that data and chained collectively stolen credentials, zero-day vulnerabilities and different assaults to discover a distant code execution path to Hugging Face’s manufacturing infrastructure.
Synthetic zero-day exploited throughout sandbox escape
In a brand new disclosure revealed Monday, JFrog acknowledged that its third-party bundle registry software program is a self-hosted JFrog Artifactory set up.
“Throughout our safety evaluation, OpenAI’s fashions recognized a beforehand unknown zero-day vulnerability in self-hosted Artifactory installations that, if exploited, may permit unintended web entry,” mentioned Yoav Landman, CTO at JFrog.
JFrog mentioned OpenAI disclosed the vulnerability rapidly, permitting the corporate to develop, check, and launch a repair for its cloud and self-hosted prospects.
Cloud prospects are already protected, however self-hosted prospects have been notified to put in a set model.
Artifactory 7.161.15 Self-Managed, launched on July 27, consists of an vital safety discover that fixes a number of vulnerabilities that may cascade and result in critical assault eventualities when nameless entry is enabled.
The 7.161.15 Self-Managed launch notes state, “This model is designed to repair a number of safety vulnerabilities that may result in critical assault eventualities when chained collectively when nameless entry is enabled.”
“Nameless entry is disabled by default and isn’t advisable for manufacturing environments because it poses extra safety dangers.”
Though JFrog didn’t listing the vulnerability in its launch notes, BleepingComputer discovered eight associated flaws when looking out CVE.org for Artifactory model 7.161.15, launched on July twenty seventh.
All CVE information have been created on July 27, the identical day that JFrog launched the zero-day. All eight corporations acknowledged that OpenAI found the vulnerability and designated Artifactory 7.161.15 as the discharge containing the repair.
Vulnerabilities are tracked as follows:
- CVE-2026-65921: Potential path traversal resulting in unlawful file writes
- CVE-2026-65923: Potential server-side request forgery in Artifactory Ansible repository processing
- CVE-2026-65924: Server-side request forgery (SSRF) over Terraform distant repositories
- CVE-2026-65925: JFrog Artifactory Cargo Server-side request forgery (SSRF) by way of distant repository
- CVE-2026-66014: Potential authentication bypass resulting in privilege escalation in Artifactory
- CVE-2026-66015: JFrog Platform accommodates an authorization flaw that might permit authenticated privilege escalation.
- CVE-2026-65617: Distant code execution could also be attainable on the Artifactory Bundle Service container.
- CVE-2026-66018: Exposing JFrog Artifactory construct setting properties
BleepingComputer contacted JFrog and OpenAI to ask which of the eight CVEs have been exploited through the incident and which vulnerabilities have been chained collectively.
Solely JFrog responded, declining to determine the CVE or present technical particulars.
“Aside from our CTO’s weblog and feedback and JFrog’s launch notes, we aren’t including any additional particulars or feedback right now,” JFrog informed BleepingComputer.
Nevertheless, a few of the CVEs found by BleepingComputer in reference to this launch could have offered performance according to a few of the assaults detailed by OpenAI.
CVE-2026-65924 is a server-side request forgery vulnerability in Artifactory’s Terraform distant repository assist.
An authenticated person, or an unauthenticated person if nameless entry is enabled on the repository, may exploit this flaw to trigger Artifactory to ship outbound HTTP requests to arbitrary locations and return response content material.
CVE-2026-65925 equally permits a person with learn entry to the Artifactory Cargo distant repository to make Artifactory requests and return responses with unintended URLs.
One other vulnerability, CVE-2026-66014, is an authentication weak spot in Artifactory’s inner request processing that might permit an attacker to escalate their privileges beneath sure situations.
These vulnerabilities may have offered the Web entry and privilege escalation capabilities described in OpenAI.
Nevertheless, it stays unclear which flaws have been exploited, how they have been chained collectively, or whether or not all eight vulnerabilities have been concerned within the sandbox escape.
Safety groups doc 54% of profitable assaults and situation a warning on solely 14%. The remainder strikes invisibly by means of the setting.
Picus’ whitepaper exhibits the right way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
