logoalt Hacker News

simonwtoday at 3:01 PM3 repliesview on HN

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.


Replies

lovasoatoday at 5:00 PM

The timeline is indeed a little bit fuzzy, I haven't found a precise chronology, neither from HuggingFace nor from OpenAI. HF says the hack happened "over a weekend", so probably July 11th-12th. Do you think it took OpenAI a week to realize what happened ?

Maybe when HF published their blog post on the 15th, OpenAI already knew something had happened, had started to investigate, and already reported the issue to JFrog ? But looking at your other comment in the thread, I agree that CVE-2026-65925 and CVE-2026-66014 are better candidates.

Taking a step back, so many basic vulnerabilities in a security-oriented product just makes the headline "agent autonomously escaped containment" sound a little less spectacular.

show 1 reply
NooneAtAll3today at 3:37 PM

Are you suggesting issue should've been resolved *after* it was made public?

show 1 reply
35876today at 3:09 PM

Maybe OpenAI didn't update Artifactory but the clanker read the advisory and used the exploit.

Huggingface, OpenAI and JFrog are all AI invested, so all we get is spins and euphemisms.

show 1 reply