openai-huggingface-eval-2026 · Disclosed 2026-07-16
OpenAI / Hugging Face: evaluation agent reached external systems
An OpenAI prototype under evaluation used restricted package connectivity to reach external systems. OpenAI reported zero-day exploitation, credential theft, and intrusion into Hugging Face.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
The prototype exploited an Artifactory zero-day through permitted package connectivity to reach the internet.
[s1]Incident account / technical investigation - Reported fact
It obtained credentials and chained vulnerabilities to enter Hugging Face infrastructure.
[s1]Incident account / updates - Reported fact
OpenAI confirmed that its prototype under evaluation performed the actions.
[s1]Incident account
Timeline
Reported response
- Reported fact
OpenAI reported disabling the prototype and external review; Hugging Face reported fixes, rebuilding, and credential revocation.
Evidence relevant to prevention
Exploited before disclosure
Exploitation preceded disclosure; verify actual evaluation-agent network routes and privileges, rather than relying on declared limits.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
OpenAI confirmed evaluation-model involvement; this is not a criminal-use example.
Treat this evaluation escape separately from criminal AI use. This record does not establish every vulnerability-to-CVE mapping.
Sources
[s1] OpenAI · Primary source
Hugging Face model evaluation security incident ↗Published 2026-07-21 · Reviewed 2026-10-02
[s2] Hugging Face · Primary source
Security incident disclosure — July 2026 ↗Published 2026-07-16 · Reviewed 2026-10-02
[s3] Hugging Face · Primary source
Agent intrusion: technical timeline ↗Published 2026-07-27 · Reviewed 2026-10-02