The AI tools your team runs in production just had their first turn on a competitive hacking stage — and they did not hold up. At Pwn2Own Ireland 2026, running October 6–8 in Cork, ZDI debuted an AI Infrastructure category alongside the usual phones and printers. Within two days, LiteLLM was cracked twice, OpenAI Codex fell on a single argument injection bug, NVIDIA Dynamo was compromised, and Chroma was broken. The running prize total through Day Two: $608,500.
Everything That Fell in Two Days
Day One set the tone immediately. Taisic Yun of the Xint team hit LiteLLM with an improper input validation flaw chained with code injection, earning a reverse shell and $40,000. Out of Bounds followed with four bugs against the same target for $15,000 more. Meanwhile, Ikotas Labs used a single argument injection in OpenAI Codex’s git command handling to walk away with another $40,000 — all before Day One closed.
Day Two continued the streak. HaeJung Yang of Out of Bounds took down NVIDIA Dynamo for $40,000. Team MAMMOTH broke into Chroma for $12,000. Additional teams hit Oracle’s Autonomous AI Database multiple times. By the close of Day Two, every AI Infrastructure target on the schedule had been successfully exploited at least once. Day Three, still underway as of this writing, has Oracle’s AI Database on the docket again.
The Codex Exploit: One Bug, $40,000, Remote Code Execution
The Codex exploit (CVE-2026-19591) deserves a closer look, because it is straightforward to a fault. The vulnerability is an argument injection in the way Codex passes arguments to git commands — specifically, insufficient neutralization of control sequences before they reach the shell. One bug. CVSS 7.8. The attack requires a target to open a malicious folder, which is not a high bar when agent workflows routinely pull external repositories.
However, this is not a novel AI vulnerability. Argument injection against shell commands is as old as CGI scripting. The fact that a world-class coding agent shipped with it in 2026 suggests the security review process for AI tooling has not kept pace with its deployment speed.
LiteLLM’s Ongoing Security Problem
LiteLLM occupies a critical position in enterprise AI stacks — proxying requests to 140-plus providers at an estimated 3.4 million downloads per day. That scale makes every vulnerability in it a high-radius problem. Moreover, 2026 has not been kind to the project. CVE-2026-42271, a command injection flaw in its MCP test endpoint that chains to unauthenticated RCE when combined with a Starlette host header bypass, landed on CISA’s Known Exploited Vulnerabilities catalog earlier in 2026. A March supply chain attack shipped backdoored PyPI versions with credential-stealing payloads. Now Pwn2Own has added two confirmed zero-days to the list.
The Pwn2Own bugs remain within ZDI’s 120-day disclosure window. Therefore, full technical details are not yet public. If you run LiteLLM in production, the practical steps now are: ensure authenticated endpoints, restrict network exposure, and monitor ZDI’s advisory feed for patch releases.
Old Bugs on New Infrastructure
The pattern across all four AI targets is hard to miss. Argument injection. Improper input validation. Code injection. These are not cutting-edge AI attack vectors. They are the same bug classes that dominated web application security for the first two decades of the internet — the same bugs that spawned OWASP, SQL injection standards, and a generation of secure coding guidelines.
Furthermore, ZDI’s own coverage of the event made the pattern explicit: the tools enterprises are rushing to deploy for retrieval-augmented generation, agent orchestration, and managed AI databases are “exposing the same classes of injection and validation bugs that have plagued web applications for two decades, just with a new interface.” The AI industry is not inventing new security problems. It is rediscovering old ones in places it forgot to look.
For additional context on AI injection risks in tools that touch your codebase, see ByteIota’s coverage of the GitHub Copilot CLI prompt injection that GitHub declined to classify as a vulnerability.
What to Do Now
Until vendor patches arrive through ZDI’s disclosure process, these are the highest-priority actions by target:
- LiteLLM: Disable unauthenticated endpoints. Apply network isolation so the proxy is not internet-facing. Ensure CVE-2026-42271 is patched (version 1.83.7 or later). Monitor ZDI advisories for Pwn2Own-specific disclosures over the next 120 days.
- OpenAI Codex (CVE-2026-19591): Treat untrusted code repositories as you would untrusted executables. Do not open them in agent environments without sandboxing or explicit review.
- Chroma: Update past version 1.5.8. Use the Rust frontend instead of the Python FastAPI server if your deployment is internet-facing. Restrict API port access at the network level — 73% of public Chroma instances ran a version with a CVSS 10.0 flaw as recently as May 2026.
- NVIDIA Dynamo: Await the vendor patch through ZDI’s standard disclosure window. Isolate Dynamo deployments from public network access in the interim.
The broader lesson is the one the web industry had to learn the hard way: infrastructure that handles untrusted input at scale needs hardening at the input layer before it reaches production. AI infrastructure is no different. Pwn2Own Ireland 2026 just proved it on stage.













