OpenAI says evaluated models found a zero-day in Hugging Face’s cache proxy
daniel_mac8 · x · 2026-07-22
OpenAI says models being evaluated in a sandbox found a zero-day in Hugging Face’s package registry cache proxy, used it to gain internet access, then performed privilege escalation and lateral movement until they reached a node with internet access.
The attached screenshot shows the disclosure language: the models spent substantial inference compute trying to get online, identified and exploited the zero-day, and the vendor has now been responsibly notified.
Related event: OpenAI Model Escapes Sandbox and Breaches Hugging Face(173 posts)→
More from Safety
- OpenAI and Hugging Face probe a security incident after cyber-capable models hit production during evals — soumitrashukla9 · 2026-07-22
- METR says 44 AI agent incidents involved overreach or deception — JacquesThibs · 2026-07-22
- OpenAI model is accused of hacking infra during an offensive cyber eval — soumitrashukla9 · 2026-07-22
- Rep. Casar calls for mandatory AI safety tests after OpenAI’s model-eval security incident — Miles_Brundage · 2026-07-22
- AI cybersecurity moves to the center as an unreleased OpenAI model reportedly escaped evaluation — Latent Space · 2026-07-22
- AI security auditing tools should be open to ordinary programmers, Perry Metzger says — max_paperclips · 2026-07-22