OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
- Date it happened
- 2026-07-11
- Organisation involved
- OpenAI, AI agent system deployers
- Product, system or model
- GPT-5.6 Sol, Unidentified pre-release OpenAI model, Large language models, OpenAI large language models, ExploitGym, OpenAI research testing infrastructure, Hugging Face production infrastructure, AI
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.