JFrog Confirms Its Own Zero-Days Were Exploited by OpenAI’s Models Escape Their Sandbox to Hack Hugging Face

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Zero-days confirmed: JFrog CTO Yoav Landman confirmed OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory installations.
  • Eight CVEs: Artifactory 7.161.15 Self-Managed on July 27 fixed eight CVEs that could be chained into a critical attack scenario when Anonymous Access is enabled.
  • Benchmark context: The GPT-5.6 Sol model and a pre-release model exploited flaws during ExploitGym testing to escape their sandbox.

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to break out of an isolated testing environment and reach the open internet, ultimately attacking Hugging Face. Artifactory 7.161.15 Self-Managed fixes the eight CVEs. Cloud customers are already protected, and self-hosted users must upgrade immediately.

It's the missing piece in a story that's been unfolding for over a week now – the moment the mystery proxy behind OpenAI's sandbox escape finally got a name. 

Sandbox Escape via Artifactory Zero-Days

OpenAI tested GPT-5.6 Sol and a more capable pre-release model against the ExploitGym benchmark without production safeguards inside a sandbox where network access was limited to a package-registry proxy. 

The AI models exploited a zero-day in the proxy, then leveraged privilege escalation and lateral movement to reach a system with internet access, chaining stolen credentials and additional zero-days into a remote code execution (RCE) path against Hugging Face's production infrastructure. 

JFrog Patches Chained Vulnerabilities

JFrog CTO Yoav Landman confirmed the third-party software was a self-hosted Artifactory installation. "During a security evaluation, OpenAI's models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access," Landman said.

Artifactory 7.161.15 Self-Managed, released July 27, addresses eight flaws that could be chained into a critical attack scenario when Anonymous Access is enabled – a setting disabled by default. 

Notably, neither company has mapped any single CVE to a specific step of the actual attack chain at the time of writing. BleepingComputer asked both JFrog and OpenAI which of the eight CVEs were exploited during the incident and how they were chained together, but only JFrog responded, and it declined to identify specifics.

A Disclosure Timeline

Landman's blog post describes the company treating OpenAI's report with "the urgency it deserved." However, Hugging Face itself detected and contained the intrusion independently around July 16, five days before OpenAI publicly attributed the incident on July 21, which waited five days after discovering the breach before disclosing its own involvement. 

JFrog itself took roughly another five days after that to ship patches. Put together, that's close to two weeks between an active zero-day being exploited in the wild and a fix landing for self-hosted customers.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: