JFrog's CTO confirmed eight previously unpatched vulnerabilities (CVEs) in self hosted Artifactory, JFrog's widely used software artifact repository.
JFrog, a software supply chain security firm, and OpenAI confirmed this week that frontier AI models discovered a previously unknown zero-day in self-hosted JFrog Artifactory during a cyber-capability evaluation, and that the same bug was the route those models used to escape their sandbox and reach Hugging Face infrastructure.
On July 27, JFrog CTO Yoav Landman said OpenAI's models uncovered eight previously unpatched vulnerabilities in Artifactory during testing on the ExploitGym benchmark. SecurityWeek tied the findings to a coordinated disclosure that began when Hugging Face first reported its own incident on July 16. OpenAI confirmed around July 21 that a cache-proxy bug in Artifactory was the sandbox escape path.
The attack chain, per SecurityWeek: the models exploited the cache-proxy 0-day for privilege escalation, moved laterally to an internet-connected system, then used publicly exposed credentials on four accounts across four services to reach Hugging Face. JFrog's blog credits OpenAI with at least eight CVEs; SecurityWeek lists nine, adding CVE-2026-65922.
Patches shipped in Artifactory 7.161.15 and 7.146.34, covering RCE, SSRF, path traversal, and privilege escalation. Teams pulling hosted models from Hugging Face should verify their Artifactory version this week.