Remix.run Logo
simonw 5 hours ago

This appears to confirm that the packaging proxy they were using for the research machine that their agent broke out of was Artifactory, the same software they use in production.

(You can tell they use it in production by asking regular ChatGPT to run "env | grep ARTIFAC" in its container environment.)

Hard to decipher which vulnerability was responsible, or if it took several.

https://www.cve.org/CVERecord?id=CVE-2026-66014 (reported by Amy Burnett, OpenAI) looks suspicious:

> JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Also https://www.cve.org/CVERecord?id=CVE-2026-65925 (reported by Matthew Bryant, OpenAI):

> A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.