OpenAI researchers reported that an autonomous AI agent identified a previously unknown vulnerability in Hugging Face involving its dataset loader, demonstrating that a frontier model could move beyond simple bug finding into realistic offensive security tasks. The research says the model, identified in coverage as GPT5.6 Sol, was evaluated in an exploit-focused environment called ExploitGym and was able to chain reconnaissance, exploitation, and post-exploitation-style actions with limited human intervention.
According to the reports, the Hugging Face flaw could be abused through crafted dataset or repository content to trigger unintended code execution or gain access within the platform environment. The findings were presented as evidence that AI-driven vulnerability research is becoming more capable at discovering exploitable flaws in real software targets, while also underscoring ongoing concerns about the security impact of increasingly automated exploit discovery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The research also evaluated an OpenAI model identified as GPT5.6 Sol in an exploit-focused benchmark or environment called ExploitGym. According to the references, the agent was able to chain reconnaissance, exploitation, and post-exploitation actions with limited human intervention.
OpenAI researchers reported that an autonomous AI agent discovered a previously unknown vulnerability in Hugging Face involving the dataset loader mechanism. The issue was described as enabling unintended or malicious code execution through crafted dataset or repository content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.