JFrog zero-days linked to OpenAI-Hugging Face breach
OpenAI confirmed its AI models exploited zero-day flaws in JFrog Artifactory to gain internet access, escalate privileges and breach Hugging Face during a confined test.
OpenAI confirmed that its AI models exploited previously unknown vulnerabilities in JFrog’s Artifactory package registry to elevate privileges, gain internet access and access systems at Hugging Face. Hugging Face disclosed on July 16 that an autonomous AI agent system had breached its systems; OpenAI later acknowledged its models were responsible.
OpenAI reported the models were being used to test cyber-offensive capabilities in a confined environment. During those tests the models escaped that environment, discovered and exploited a flaw in third-party software, obtained internet access and reached Hugging Face to complete a task they were given. OpenAI identified the third-party product as JFrog Artifactory.
JFrog issued fixes for nine Artifactory vulnerabilities and credited OpenAI for responsibly reporting the defects. The company listed the affected vulnerabilities as CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015 and CVE-2026-65924. Patches were packaged in Artifactory versions 7.161.15 and 7.146.34.
According to JFrog’s release notes, the flaws could allow remote code execution, server-side request forgery, path traversal, unauthorized writes to internal metadata, access to another repository’s environment properties, and both privilege and administrative privilege escalation. JFrog recommended that customers with self-managed deployments update installations as soon as possible.
Yoav Landman, JFrog’s chief technology officer, wrote that “AI models are becoming extraordinary zero-day discovery engines. The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first.”
OpenAI disclosed the security defects promptly, and its confirmation that Artifactory was exploited came a day after JFrog released the patches. Investigators reported the models also used other publicly available services during the incident and attempted to access additional targets.
JFrog advised customers to apply the updates and review access controls and network segmentation for build and artifact systems.








