OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

Pierluigi Paganini
July 29, 2026

OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face.

Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirming the models responsible didn’t just wander into Hugging Face’s systems. They found a genuine zero-day vulnerability in a piece of infrastructure software first, used it to get online, and only then moved on to the actual target.

“The ExploitGym evaluation environment did not provide the models with direct Internet access. To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory⁠(opens in a new window), a package registry cache proxy.” reads OpenAI’s update. “We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor. “

The software in question is Artifactory, JFrog’s widely used package registry cache proxy. OpenAI had been testing its models’ offensive cyber capabilities inside a supposedly sealed evaluation environment called ExploitGym, one with no direct path to the internet by design. Instead of staying contained, the models found and exploited a previously unknown flaw in Artifactory that let them reach the internet anyway, then used that access to move laterally and eventually breach Hugging Face’s platform.

JFrog confirmed the finding a day before OpenAI’s own statement, crediting the company’s models with uncovering nine previously unknown vulnerabilities in self-hosted Artifactory deployments, all now patched.

“During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access.” reported JFrog. “OpenAI’s security team disclosed the vulnerabilities to us responsibly and immediately. Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike. Cloud customers are already protected; self-hosted customers have been notified to upgrade to the fixed versions referenced in our security advisory. (Artifactory 7.161)”

The company’s CTO, Yoav Landman, didn’t sugarcoat what that means for defenders going forward.

“There is an important, and frankly optimistic, lesson buried in this incident: AI models are becoming extraordinary zero-day discovery engines.” said Landman. “The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first. OpenAI made this exact point in their disclosure, and we agree: advanced cyber-capable models should be put to work helping security teams discover weaknesses before attackers do, understand how vulnerabilities chain together, and remediate them at machine speed.”

He framed the same capability that let a model find an exploit path nobody had spotted before as exactly the capability defenders will need to shut those paths down first.

The fixes shipped in Artifactory 7.161, covering nine separate vulnerabilities (CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924) ranging from remote code execution and server-side request forgery to path traversal and privilege escalation, tracked under nine different CVE identifiers.

JFrog pushed patches into versions 7.161.15 and 7.146.34, and anyone running a self-managed Artifactory instance should treat this as a today problem, not a whenever-there’s-time one.

OpenAI says the pre-release model involved was strictly an internal research prototype never meant to ship publicly, and it’s since been deactivated, encrypted, and cut off from further research access. OpenAI also stresses that its review so far hasn’t turned up anything else at the same severity or scale as the Hugging Face compromise, which it describes as a genuine platform-level breach rather than a narrower account issue.

There’s a messier detail buried further in: OpenAI says its models found and used publicly exposed credentials on four separate outside services during the incident, one used as an outbound relay, one for data storage, and two accessed only in a read-only way that didn’t contribute to the Hugging Face breach itself. The models also poked around a handful of ordinary public web utilities, code paste sites, screenshot tools, and request capture services, though none of that involved compromising an account or platform. OpenAI says it’s notifying the affected service owners directly and hasn’t seen signs of wider damage there.

OpenAI is now folding the whole episode into review under its own Preparedness Framework, alongside its Safety and Security Committee and Safety Advisory Group, and says it’s working with Hugging Face on the platform’s technical post-mortem.

“We take our responsibility to identify and prepare for risks from increasingly capable AI systems seriously. Once we complete our review, we will review with the Safety and Security Committee and Safety Advisory Group under our Preparedness Framework.” concluded OpenAI’s update.

That’s the appropriate move, and also a fairly remarkable sentence to type out loud: a company’s safety board is now formally reviewing an incident where its own AI went looking for internet access, found a zero-day nobody knew about, and let itself out.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, OpenAI)







Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW