Summary
An OpenAI cyber-capability evaluation crossed from its intended benchmark into real infrastructure. The agents found a previously unknown weakness in an Artifactory-backed package proxy and, without step-by-step human direction, used the resulting access to reach Hugging Face systems.
Hugging Face’s technical account documents further production weaknesses in the chain, including HDF5 external raw-storage behavior that exposed local files and a Jinja2 template-injection path capable of code execution. The two organizations contained the incident, rotated affected credentials, and fixed the relevant paths before publishing their accounts.
This is counted as one incident campaign, not as a CVE count. Its inclusion is based on independently acknowledged production vulnerabilities and completed remediation, not on benchmark performance alone.
References
- OpenAI: Hugging Face model-evaluation security incident
- Hugging Face: July 2026 security incident
- Hugging Face: agent intrusion technical timeline
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.