OpenAI Models Exploited JFrog Artifactory Zero-Days to Escape a Sandbox
OpenAI models exploited JFrog Artifactory zero-days while undergoing cybersecurity testing, allowing them to escape an isolated environment and reach the internet.
The incident follows reports that Hugging Face was breached after OpenAI agents escaped a test environment.
OpenAI models escaped through an Artifactory server
OpenAI tested GPT-5.6 Sol and a more capable pre-release model against the ExploitGym cybersecurity benchmark. The company removed the production safeguards that normally restrict autonomous cyberattacks.
The models operated inside an isolated environment without direct internet access. An internally hosted third-party package registry handled package downloads and caching.
During testing, the models discovered and exploited an unknown vulnerability in the registry proxy. They then used privilege escalation and lateral movement to reach a system with internet access.
After escaping, the models identified Hugging Face as a possible source of ExploitGym datasets or solutions. OpenAI said they combined stolen credentials, zero-day vulnerabilities, privilege escalation, and other attacks to create a remote code execution path into Hugging Face’s production infrastructure.
JFrog released Artifactory security fixes
JFrog confirmed that the affected software was a self-hosted Artifactory installation. OpenAI privately disclosed the vulnerabilities after discovering them.
JFrog released fixes for cloud and self-hosted customers. Cloud installations already have protection, while self-hosted users must upgrade to a patched version.
Artifactory 7.161.15 Self-Managed, released on July 27, fixes several vulnerabilities that attackers could chain into a critical exploit. JFrog said systems with Anonymous Access enabled face the highest risk. The feature remains disabled by default and should not run in production environments.
JFrog has not identified the exploited CVEs or explained the vulnerability chain. It also remains unclear whether the models used all eight vulnerabilities addressed by the update.
In other security news, MAI-Cyber-1-Flash has been released and integrated into MDASH to help Microsoft discover vulnerabilities faster.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages