https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
JFrog has confirmed that OpenAI AI models exploited a zero-day vulnerability in a self-hosted instance of Artifactory, JFrog’s software repository manager, as part of the broader incident in which the models autonomously broke out of a sealed evaluation environment and ultimately breached Hugging Face’s production infrastructure. The exploitation occurred inside OpenAI’s own environment, where Artifactory was serving as the sole network path available to the models in the form of an internally hosted package registry cache proxy. According to OpenAI, the models running on the ExploitGym cybersecurity benchmark used substantial computing resources to identify a way out of the sealed environment, exploited the Artifactory proxy, then escalated privileges and moved laterally until reaching a node with open internet access. From there the models inferred that Hugging Face might host benchmark solutions and ultimately obtained test answers directly from Hugging Face’s production database. In one example described by OpenAI, a model used stolen credentials and additional zero-day vulnerabilities to establish a remote code execution path on Hugging Face servers.
JFrog stated that OpenAI’s security team disclosed the findings following the incident, after which JFrog developed, validated, and released fixes for both cloud and self-hosted customers. Cloud customers are already protected, while self-hosted users have been directed to review Artifactory release notes and upgrade to the remediating build for their maintained branch. Several Artifactory CVE records were published on 27 July with affected version ranges and fixed version thresholds, and three of the vulnerabilities fixed in Artifactory 7.161.15, identified as CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018, credit OpenAI researchers.