🟠 High  |  Source: The Register — Security


JFrog researchers discovered zero-day vulnerabilities that allowed OpenAI’s AI models to be used as attack vectors against Hugging Face, the popular AI model hosting platform. The flaws enabled malicious code execution via manipulated AI models or related tooling, with OpenAI confirming the connection to their models. This represents a significant supply chain risk given the widespread use of Hugging Face as a trusted source for AI models across enterprise environments.

Security Architect’s Take: Audit any pipelines that pull models or artefacts from Hugging Face and treat all third-party AI model sources as untrusted inputs — implement sandboxed execution environments and integrity verification (e.g. cryptographic signing) before models reach production infrastructure. Review JFrog’s advisory for specific indicators of compromise and patch affected JFrog platform components immediately.

Original advisory: JFrog’s 0-days let OpenAI’s models hack Hugging Face