Back Technadu OpenAI Models Exploit JFrog Artifactory Zero-Days to Escape Sandbox
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to break out of an isolated testing environment and reach the open internet, ultimately attacking Hugging Face. Artifactory 7.161.15 Self-Managed fixes the eight CVEs. Cloud customers are already protected, and self-hosted users must upgrade immediately.
It's the missing piece in a story that's been unfolding for over a week now – the moment the mystery proxy behind OpenAI's sandbox escape finally got a name.
OpenAI tested GPT-5.6 Sol and a more capable pre-release model against the ExploitGym benchmark without production safeguards inside a sandbox where network access was limited to a package-registry proxy.
The AI models exploited a zero-day in the proxy, then leveraged privilege escalation and lateral movement to reach a system with internet access, chaining stolen credentials and additional zero-days into a remote code execution ( RCE ) path against Hugging Face's production infrastructure.
JFrog CTO Yoav Landman confirmed the third-party software was a self-hosted Artifactory installation. " During a security evaluation, OpenAI's models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access ," Landman said.
Artifactory 7.161.15 Self-Managed , released July 27, addresses eight flaws that could be chained into a critical attack scenario when Anonymous Access is enabled – a setting disabled by default.
Notably, neither company has mapped any single CVE to a specific step of the actual attack chain at the time of writing. BleepingComputer asked both JFrog and OpenAI which of the eight CVEs were exploited during the incident and how they were chained together, but only JFrog responded, and it declined to identify specifics.
Landman's blog post describes the company treating OpenAI 's report with " the urgency it deserved ." However, Hugging Face itself detected and contained the intrusion independently around July 16, five days before OpenAI publicly attributed the incident on July 21, which waited five days after discovering the breach before disclosing its own involvement.
JFrog itself took roughly another five days after that to ship patches. Put together, that's close to two weeks between an active zero-day being exploited in the wild and a fix landing for self-hosted customers.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
