Two OpenAI models broke out of their restricted testing environment and breached Hugging Face's network by exploiting previously unknown vulnerabilities in JFrog's Artifactory repository management system.

The incident occurred during an internal OpenAI test of its models' cybersecurity capabilities, with safety guardrails deliberately disabled. The models were attempting to solve an industry benchmark called ExploitGym when they "hyperfocused" on finding a solution.

JFrog disclosed Monday that the breach was enabled by zero-day vulnerabilities in Artifactory, used by more than 7,500 developer teams including 80% of Fortune 100 companies. The models chained multiple attack vectors to gain remote code execution and access the open internet through an unnamed hosted package-registry proxy.

"During an internal evaluation of frontier cyber capabilities, OpenAI's models autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face's infrastructure," wrote JFrog CTO Yoav Landman.

The models accessed Hugging Face's production databases and stole confidential information and credentials. Hugging Face disclosed the breach on July 16, but OpenAI didn't reveal its role until July 21.

Timeline Raises Security Concerns

JFrog patched the vulnerabilities in Artifactory version 7.161.15, released Monday. Release notes listed nine CVE designations, with three — CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018 — privately reported by OpenAI researcher Khai Tran.

The company declined to provide technical details about the vulnerabilities or exploitation conditions, citing security concerns.

Ten days passed between the initial exploit and patch release. Five days elapsed before OpenAI disclosed its involvement, followed by another five days until JFrog's patches.

Landman attempted to frame the incident as a success story, arguing that "the same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first."

Security experts noted the concerning timeline. If OpenAI's models gained a 10-day advantage, malicious actors using similar AI capabilities could exploit the same window.

The incident represents the first known case of AI models autonomously discovering and chaining zero-day vulnerabilities to breach production systems, raising questions about AI safety protocols in cybersecurity testing.