Remix.run Logo
lovasoa 5 hours ago

What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification.

https://www.youtube.com/watch?v=q2KCrmQz9WE

simonw 4 hours ago | parent | next [-]

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.

lovasoa 2 hours ago | parent | next [-]

The timeline is indeed a little bit fuzzy, I haven't found a precise chronology, neither from HuggingFace nor from OpenAI. HF says the hack happened "over a weekend", so probably July 11th-12th. Do you think it took OpenAI a week to realize what happened ?

Maybe when HF published their blog post on the 15th, OpenAI already knew something had happened, had started to investigate, and already reported the issue to JFrog ? But looking at your other comment in the thread, I agree that CVE-2026-65925 and CVE-2026-66014 are better candidates.

Taking a step back, so many basic vulnerabilities in a security-oriented product just makes the headline "agent autonomously escaped containment" sound a little less spectacular.

simonw an hour ago | parent [-]

> Do you think it took OpenAI a week to realize what happened ?

Apparently it did take them a while. This report here https://cloudsecurityalliance.org/artifacts/hugging-face-cis... includes extra details from a conversation Hugging Face:

> The intrusion lasted about four days: two days were spent on reconnaissance, followed by one silent day and a final day of intense activity.

That suggests OpenAI didn't spot what was happening for four days.

NooneAtAll3 3 hours ago | parent | prev | next [-]

Are you suggesting issue should've been resolved *after* it was made public?

simonw 3 hours ago | parent [-]

I'm suggesting that you can't release a fix for an issue that hasn't been reported to you yet.

35876 4 hours ago | parent | prev [-]

Maybe OpenAI didn't update Artifactory but the clanker read the advisory and used the exploit.

Huggingface, OpenAI and JFrog are all AI invested, so all we get is spins and euphemisms.

K3UL 3 hours ago | parent [-]

This seems unlikely as it would mean JFrog knew the vulnerability before OpenAI, which this blog posts clearly says the opposite

patmorgan23 4 hours ago | parent | prev [-]

I believe the technical term for that is "big oof"