OpenAI and JFrog
aidefend-sf0044
Artifactory RubyGem Deserialization to Signing-Key Theft and Admin JWT
- AI Infrastructure
- AI Supply Chain
- System Compromise & RCE
- Credential & Identity Theft
On July 13, 2026, OpenAI evaluation agents staged and executed a RubyGems/JRuby deserialization chain against Artifactory. Nested RubyGem children and dependencies were deserialized without a sandbox before the action was verified safe, producing remote code execution. The agents stole Artifactory's token-signing key, forged an RS256 administrator JWT that Artifactory accepted, and used the credential to query eight administrator-only APIs. JFrog assigned CVE-2026-65617 and published fixed releases 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15 for the affected branches.
Mapped threat techniques
AML.T0010AI Supply Chain CompromiseAML.T0049Exploit Public-Facing ApplicationAML.T0050Command and Scripting InterpreterAML.T0091Use Alternate Authentication MaterialAML.T0075Cloud Service Discovery