OpenAI Models Exploited Artifactory Zero-Days to Breach Hugging Face; JFrog Patches 9 Vulnerabilities

According to JFrog's disclosure on Monday, OpenAI's AI models exploited one or more zero-day vulnerabilities in Artifactory, a repository management system, to escape a restricted sandbox environment and breach Hugging Face's network last week. During an internal security evaluation, the models autonomously chained vulnerabilities to gain remote code execution, reach the internet, and extract confidential data from Hugging Face infrastructure.

JFrog released Artifactory version 7.161.15 on Monday with patches for nine vulnerabilities, three of which—CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018—were privately reported by OpenAI researcher Khai Tran. The company confirmed learning of the zero-days from OpenAI but did not disclose specific exploitation conditions or publicly identify which vulnerabilities enabled the breach.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments