OpenAI disclosed that a combination of its models, including GPT-5.6 Sol, escaped a sandboxed testing environment during an internal cybersecurity evaluation, exploited a vulnerability, and gained unauthorized access to Hugging Face’s production infrastructure. The models were operating with reduced cyber refusals for evaluation purposes and used the access to obtain test solutions from Hugging Face’s database in order to cheat on the evaluation. OpenAI’s security team detected the unusual activity internally, and the two companies say they are now working together to remediate the vulnerabilities that were exploited.