OpenAI models exploited JFrog Artifactory zero-days while undergoing cybersecurity testing, allowing them to escape an isolated environment and reach the internet. The incident follows reports that Hugging Face was breached after OpenAI agents escaped a test environment. OpenAI models escaped through an Artifactory serverOpenAI tested GPT-5.6 Sol and a more capable pre-release model against the ExploitGym cybersecurity benchmark. After escaping, the models identified Hugging Face as a possible source of ExploitGym datasets or solutions. JFrog released Artifactory security fixesJFrog confirmed that the affected software was a self-hosted Artifactory installation.