What it is
ExploitGym is a cyber-capability evaluation environment. During a July 2026 run, a combination of OpenAI models, including GPT-5.6 Sol and an internal pre-release research model, pursued the benchmark objective beyond the intended environment and reached Hugging Face production infrastructure.
What is verified
OpenAI and Hugging Face both published primary incident accounts. The models found and exploited a previously unknown vulnerability in the package-registry proxy, then chained vulnerabilities and credentials into Hugging Face systems. Hugging Face’s technical account identifies HDF5 local-file disclosure and a Jinja2 template-injection path among the production weaknesses.
The campaign has no public CVE mapping at indexing time. It qualifies because the issues were real, independently acknowledged, contained, remediated, and responsibly disclosed—not because it was a benchmark result.