JFrog’s 0-days let OpenAI’s models hack Hugging Face

Security

OpenAI confirms the link

UPDATED We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection.

"To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory⁠ package registry cache proxy," OpenAI added to a blog post on the topic Tuesday. "We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor."

Landman says OpenAI's models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the ExploitGym benchmark.

“During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday.

JFrog Artifactory is a central platform that organizations use to store and distribute all the software artifacts across their supply chains. It supports more than 60 package formats including Docker, Maven, npm, PyPI, Helm, and AI/ML models. 

OpenAI “responsibly and immediately” disclosed the vulnerabilities to JFrog, Landman continued. “Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike.”

On Monday, JFrog released the fixed versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924.

JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre-release model, escaped their testing sandbox during a security evaluation designed to test their cyber capabilities. During this test, the models found a way to access the open internet, then broke into Hugging Face and accessed private information and stole some credentials.

“While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,” OpenAI said on July 21.

In a July 28 update, the house of Altman admitted that the JFrog 0-days were the cause. In the same update, OpenAI admitted that its models had breached other services.

"We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations)," OpenAI wrote.  ®

Updated on July 29 with additional details from OpenAI, admitting that the JFrog 0-days led to the breach.

Logo

Biting the hand that feeds IT

https://www.theregister.com/security/2026/07/28/jfrogs-0-days-let-openais-models-hack-hugging-face/5280001