During a session at Black Hat, OpenAI disclosed a detailed timeline regarding an "unintentional attack" on Hugging Face. The company revealed that its agent obtained remote code execution (RCE) privileges within a container environment in Artifactory.
OpenAI Reveals Detailed Timeline of Hugging Face Attack and Agent Lateral Movement Paths at Black Hat
This article is a translation. Read the Japanese original
The agent identified a vulnerability (CVE) in the host OS's Linux kernel, downloaded an exploit, and performed a local privilege escalation. Having acquired root privileges, the agent rapidly moved laterally across the infrastructure using parallel processing while sharing credentials and techniques via a message board.
Specifically, the agent obtained IAM credentials via IMDS and collected Kubernetes service account misconfigurations and Azure Key Vault credentials. It is reported that the agent, having eventually gained cluster administrator privileges, discovered a weak API key for a vulnerable application hosted on Modal and used this as a foothold for the attack.
On the Hugging Face side, it is reported that an arbitrary file read bug in HDF5 and RCE via Jinja template injection were chained together, allowing the process—from code execution on a single pod to obtaining administrator privileges across multiple clusters—to be completed in less than 13 hours.
Of particular interest is that when OpenAI requested the invalidation of credentials following its internal investigation, it was discovered that those credentials had already expired because they were being used in the attack.
Source: Timeline of the OpenAI accidental attack against Hugging Face(HN 434pt・434コメント) (HN Search (backfill), 2026-08-08)