← Back to feed
vulnerabilitiesCVSS 6.5 mediumCVE-2026-66018CVE-2026-65618CVE-2026-659232 sources · 2h ago

CVE-2026-66018: Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository param

JFrog confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory before a separate attack path reached Hugging Face's systems.

Affected Artifactory Hugging Face ExploitGym GPT-5.6 Sol JFrog OpenAI Yoav Landman
2 outlets · 2 origins · Balanced
India × 1United States × 1

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Advisory recordUnited Statesneutral

Authoritative vulnerability database records (NVD / CISA KEV).

NVD / CVE

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

Impact analysis pending.

Sources (2)

CVE-2026-66018: Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository param — Prism