On October 6, 2026, the first day of the Pwn2Own competition held in Cork, Ireland, security researchers mounted an intensive wave of attacks on AI infrastructure. Across 21 attempts that day, LiteLLM was breached by two independent teams in succession, OpenAI Codex was felled by a single vulnerability, and Oracle's autonomous AI database also failed to hold. According to the official Zero Day Initiative (ZDI) blog, researchers demonstrated 32 zero-day vulnerabilities on day one, earning more than $380,000 in prize money.
All targets were production versions of the software, and the rules required a complete exploit chain to be demonstrated on site.
LiteLLM: Broken Twice in the Same Day
Security researcher Taisic Yun of team Xint struck first, combining an improper input validation flaw with code injection to obtain a reverse shell on LiteLLM and win $40,000. A reverse shell means the attacker controls the target machine and can execute arbitrary commands remotely.
Hours later, team Out of Bounds (HaeJung Yang and ByungYoung Yi) breached LiteLLM again using four vulnerabilities, two of which were known issues, ultimately earning $15,000. The same product being independently broken by two teams unaware of each other on the same day suggests the flaws lie dormant in core processing logic.
LiteLLM is an open-source enterprise LLM gateway that uniformly proxies API calls to more than 140 model providers and is downloaded roughly 3.4 million times a day. Many enterprises deploy it between their internal networks and external AI services, where it serves as a traffic hub and permission control layer. A compromised gateway means the request data, API keys, and downstream systems of every upstream model are left exposed.
The Codex Flaw: A Precise Recurrence of an Old Malady in a New Setting
Ikotas Labs took down OpenAI Codex with a parameter injection vulnerability, earning $40,000. According to ZDI, the flaw is tracked as CVE-2026-19591, and stems from insufficient filtering of the parameters Codex passes when invoking git commands, allowing an attacker to smuggle shell control sequences into the command chain.
Parameter injection was systematically studied back in the era of CGI scripts, and the web security field has had mature defensive standards in place for decades. An analysis by byteiota.com notes that a world-class code-generation agent shipped in 2026 carrying this flaw points to a deeper issue: code-generation tools are inherently more complex when it comes to handling the boundaries of external input, which in turn raises the difficulty of security review. The tools themselves are built to write code, and the distance between their input path and their command execution path is shorter than in conventional software.
Known but Unpatched: A More Dangerous Signal Than Zero-Days
Of the four vulnerabilities Out of Bounds used to break LiteLLM, two were already known to the vendor. In its day-one blog, ZDI explicitly noted that some of the flaws involved in the repeated breaches of the Samsung Galaxy S26 were issues the vendor knew about but had yet to patch.
An analysis by pulse.adyog.com notes that a vulnerability is also a timer: it starts running the moment it is discovered and does not stop until a patch is released. For enterprise users, the existence of known vulnerabilities indicates that patch prioritization has gone wrong.
LiteLLM suffered a supply chain attack in March 2026, when malicious PyPI packages were slipped into its distribution channels. The two day-one breakthroughs at Pwn2Own came after this backdrop. The vendor has released version 1.83.7 and above as a fix, but version control tends to lag in large-scale deployments.
The True Dimensions of Enterprise Deployment Risk
The attack surface of AI infrastructure differs structurally from that of traditional web applications. A gateway like LiteLLM carries all traffic between an enterprise's internal business systems and multiple external AI services. Once breached, the attacker gains not merely server privileges but visibility into the entire request channel, including user input, model output, API credentials, and usage patterns.
As a code-generation tool, OpenAI Codex is typically integrated with code repositories and CI/CD pipelines. The command execution privileges obtained through parameter injection offer broader room for lateral movement in that kind of integrated environment.
The competition rules of Pwn2Own dictate that vulnerability details will not be publicly disclosed until vendors have completed their fixes. As a result, enterprises currently have limited information available and can only rely on vendor update notices.
The Industry Is Reinventing What It Should Never Have Forgotten
Nearly all the vulnerability types exposed on day one of Pwn2Own Ireland belong to classic categories: input validation failures, code injection, and parameter injection. These are old problems that were thoroughly studied in the web security field decades ago. What makes AI systems distinctive is that they draw large amounts of external text into command execution chains, and this happens at extremely high frequency across almost every core functional path.
Traditional software has relatively clear boundaries around external input: an HTTP request comes in, is validated, and then goes to a database or renders a page. AI gateways and code-generation tools break that boundary: natural language text submitted by a user may directly shape how backend commands are constructed. This demands that security review reach into every code path that could carry external input into an execution context, rather than just applying a single layer of filtering at the API entry point.
The day-one results show a clear gap between the security maturity of AI infrastructure products and the scale at which they are deployed in enterprises. The demonstration of 32 zero-day vulnerabilities in a single day is a concentrated expression of the fact that security engineering practices across the AI application layer have yet to catch up with the pace of product expansion.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接