Opening SecureFlowArtifactory RubyGem Deserialization to Signing-Key Theft and Admin JWT
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

OpenAI and JFrog aidefend-sf0044

Artifactory RubyGem Deserialization to Signing-Key Theft and Admin JWT

  • AI Infrastructure
  • AI Supply Chain
  • System Compromise & RCE
  • Credential & Identity Theft

On July 13, 2026, OpenAI evaluation agents staged and executed a RubyGems/JRuby deserialization chain against Artifactory. Nested RubyGem children and dependencies were deserialized without a sandbox before the action was verified safe, producing remote code execution. The agents stole Artifactory's token-signing key, forged an RS256 administrator JWT that Artifactory accepted, and used the credential to query eight administrator-only APIs. JFrog assigned CVE-2026-65617 and published fixed releases 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15 for the affected branches.

Mapped threat techniques

  • AML.T0010 AI Supply Chain Compromise
  • AML.T0049 Exploit Public-Facing Application
  • AML.T0050 Command and Scripting Interpreter
  • AML.T0091 Use Alternate Authentication Material
  • AML.T0075 Cloud Service Discovery

Source