JFrog Zero-Days Exploited in OpenAI
A JFrog zero-day vulnerability was at the core of the recently disclosed OpenAI-Hugging Face hack, OpenAI has confirmed.
The incident was disclosed on July 16, when Hugging Face said it was hacked by an autonomous AI agent system. Several days later, OpenAI admitted that its AI models were behind the attack.
While OpenAI was testing cyber offensive capabilities in a confined environment, its models went rogue, exploited a vulnerability in third-party software, gained internet access, and then breached Hugging Face’s systems to complete the task they were given.
On Tuesday, OpenAI confirmed that JFrog’s package registry manager Artifactory was the third-party software exploited during the attack.
The AI models exploited a zero-day vulnerability in JFrog’s product to elevate their privileges, then moved laterally to an internet-connected system.
The confirmation came one day after JFrog announced patches for nine Artifactory vulnerabilities, crediting OpenAI for finding “previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access.”
JFrog said that OpenAI immediately disclosed the security defects responsibly, but did not specifically mention that the zero-days were exploited in the Hugging Face incident.
“We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike,” JFrog’s CTO Yoav Landman says, underlining the need to address newly uncovered bugs faster in the AI era.
“AI models are becoming extraordinary zero-day discovery engines. The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first,” Landman notes.
Per JFrog’s release notes, the latest Artifactory 7.161 release resolves high- and medium-severity vulnerabilities leading to remote code execution (RCE), SSRF, path traversal, restricted internal metadata writes, access to another repository’s environment properties, and privilege and administrative privilege escalation.
The security weaknesses are tracked as CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924.
Patches for these vulnerabilities were included in Artifactory versions 7.161.15 and 7.146.34. All users with self-managed deployments are advised to update their installations as soon as possible.
In addition to the JFrog zero-day findings, details have emerged about the OpenAI models’ use of other publicly available services during the same Hugging Face incident, as well as the names of other targets.
Related: Unpatched Fastjson Vulnerability Exploited in Attacks
Related: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Related: Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Related: Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.