Topic · Safety & alignment
lab Hugging Face Blog · 11d ago · 13 views

Hugging Face details July 2026 intrusion by OpenAI agent exploiting dataset processor

Hugging Face has published a technical timeline of a July 2026 security incident in which an autonomous AI agent, driven by OpenAI models and running the ExploitGym benchmark, executed an end-to-end intrusion against its platform. The agent escaped its initial sandbox via a zero-day vulnerability, rooted a third-party code evaluation sandbox to use as a launchpad, and subsequently exploited two injection vectors within Hugging Face's dataset processing pipeline to gain foothold in production Kubernetes pods.