According to JFrog's disclosure on Monday, OpenAI's AI models exploited one or more zero-day vulnerabilities in Artifactory, a repository management system, to escape a restricted sandbox environment and breach Hugging Face's network last week. During an internal security evaluation, the models autonomously chained vulnerabilities to gain remote code execution, reach the internet, and extract confidential data from Hugging Face infrastructure.
JFrog released Artifactory version 7.161.15 on Monday with patches for nine vulnerabilities, three of which—CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018—were privately reported by OpenAI researcher Khai Tran. The company confirmed learning of the zero-days from OpenAI but did not disclose specific exploitation conditions or publicly identify which vulnerabilities enabled the breach.