watch Pwn2own Ireland 2026 · AI Security

Pwn2Own Ireland 2026 Breaks LiteLLM, Codex, Dynamo, Chroma and Oracle's AI Database: What Is Known and What to Harden

Pwn2Own Ireland 2026 poster: five AI targets broken, no CVEs yet
AK

Threat intelligence editor · Published Oct 8, 2026, 10:51 PM EDT

Five AI targets fell at Pwn2Own Ireland 2026. No CVEs or bug details are public yet, so here is what ZDI confirmed and what to harden now.

Researchers compromised five AI targets at Pwn2Own Ireland 2026 in Cork between 6 and 8 October: four AI infrastructure products (LiteLLM, Dynamo, Chroma and Oracle Autonomous AI Database) and OpenAI Codex, which sits in the separate Coding Agent category. Ikotas Labs took Codex with a single argument injection bug. The contest first added an AI category at Pwn2Own Berlin in 2025, where Chroma was also broken, so this is a second round, not a one-off. No CVE identifiers or technical write-ups exist yet. Anyone running these products should treat this as an early warning, not a patch notice.

What is confirmed

The Zero Day Initiative (ZDI) results pages report the following AI-related entries. Figures are ZDI's; "points" are Master of Pwn points.

DayTargetTeamReported resultPayout
1LiteLLMXint (Taisic Yun)Improper input validation plus code injection; reverse shell$40,000
1LiteLLMOut of Bounds (HaeJung Yang, ByungYoung Yi)4 bugs, 2 previously known; collision$15,000
1OpenAI CodexIkotas LabsSingle argument injection bug$40,000
1Oracle Autonomous AI DatabaseVinSOC5 bugs$40,000
1ChromaVinSOCFailed within the time allowednone
2DynamoOut of Bounds (HaeJung Yang)Success (bug class not stated)$40,000
2ChromaEugene (@k3vg3n)Failednone
2ChromaTeam MAMMOTH2 collisions, 1 zero-day$12,000
2ChromaAlessandro Fanio Gonzalez2 N-days, 1 collision$4,500
2Oracle Autonomous AI DatabaseXint (Taisic Yun)3 collisions, 2 unique zero-days$14,000
2Oracle Autonomous AI DatabaseIkotas Labs7-bug chain ending in use-after-free and type confusion$10,000
3Oracle Autonomous AI DatabaseOtterSec4-bug chain: 3 collisions, 1 zero-day$6,250
3Oracle Autonomous AI DatabasePlatform Security5 bugs: 4 collisions, 1 unique chain$6,000

On Day 2, the AI Infrastructure entries add up to $80,500 across six attempts, five of them successful (our sum of the figures above). Ikotas Labs was named Master of Pwn after a $300,000, 30-point Google Pixel 10 entry, per ZDI's Day 3 post; that entry is outside the AI category. ZDI's Day 3 post reports no successful Chroma exploit, and we did not find a reported outcome for a scheduled Day 3 Chroma attempt by Rintaro Kawasugi of GMO Flatt Security. Postgres pgvector, also a listed target, appears in the rules but not in the schedule we read.

What "collision" means

The ZDI posts use the term without defining it. The contest rules require bugs to be "unknown, unpublished, and/or not previously reported to the vendor or the Sponsor," and say that if an entry uses a previously known vulnerability, the Sponsor may accept it at a reduced prize. A collision therefore means at least one bug in the chain was already known to the vendor or to ZDI, which is why the Oracle and Chroma payouts on Days 2 and 3 sit well below the $40,000 and $20,000 listed ceilings. It does not mean a patch exists: the rules' own example is a known vulnerability for which the vendor has not yet released a patch, and ZDI's Day 1 post says the same of a collision on another target ("already known to the vendor (yet unpatched)"). The page does not explain why Ikotas Labs' 7-bug Oracle chain paid $10,000, so we draw no conclusion.

Rules that shape the results

The rules describe the conditions ZDI accepted, which is the closest thing to an exposure statement until details are published.

  • Default configuration. Targets were fully set up in default configuration.
  • AI Infrastructure. Authentication was configured where the product offers it, and the entry had to bypass it. Dynamo ran on Ubuntu 24.04 x64. Contestants attacked from a laptop on the contest network, so the setting was network-adjacent, not necessarily internet-facing.
  • Codex. Default configuration on Windows 11 25H2 with the sandbox and isolation on and no unsafe modes such as --dangerously-skip-permissions. The entry had to run code outside the sandbox through a contestant-controlled repository, web page or media file. Allowed scenarios include an untrusted workspace before any trust prompt, and opening a project in the GUI.

So the tested Codex was the stock install with its sandbox on, not a loosened one. Anthropic's Claude Code was also a listed $40,000 coding-agent target, but we saw no entry for it on the schedule.

What is not known

  • No CVEs or technical details. ZDI has published none of the bug details. Do not trust posts claiming to describe the exploits.
  • Disclosure window. The rules say winning bugs are disclosed to affected vendors but specify no window. BleepingComputer says vendors have 90 days to release updates before ZDI publicly discloses the bugs, while ZDI's own disclosure policy gives vendors 120 days. We cannot say which applies to each bug.
  • Vendor statements and patch status. We found no statement or advisory from LiteLLM (BerriAI), OpenAI, Oracle, NVIDIA or Chroma about the contest bugs as of 9 October.
  • Version scope. ZDI's pages we read do not name the exact versions attacked.
  • Headline totals. BleepingComputer's Day 1 report cites "32 zero-days" and "$388,500" for the first day only. We could not verify these on ZDI's pages and do not use them.

An older LiteLLM flaw, for reference

Separate from the contest, CVE-2026-59822, an improper authentication flaw in LiteLLM's MCP Streamable HTTP endpoint that NVD lists as fixed in version 1.84.0, was added to CISA's Known Exploited Vulnerabilities catalog on 2 September 2026 (due date 16 September; ransomware use listed as Unknown). CISA's entry links the LiteLLM advisory. It is unrelated to the Cork entries as far as the public record shows. ThreatFrontier has covered earlier LiteLLM issues, including AI Gateway Compromise: Chained Starlette and LiteLLM Flaws Expose Foundation Model Keys, the LiteLLM salt-key proxy admin flaw and Google's count of 141 exploited flaws.

What to harden (inference)

Everything in this section is our inference from the category rules and general practice, not vendor or ZDI guidance.

  • Do not rely on a login page. Authentication was configured on the infrastructure targets and the entries still had to get past it, and the attacks came from the local network. Put LiteLLM, Chroma, Dynamo and database endpoints on a private network or VPN with an allowlist, and treat other hosts on that network as potential attackers. We do not know which feature or setting was abused, so we cannot say that turning anything off helps.
  • Inventory first. Find where LiteLLM proxies, Chroma instances, Dynamo deployments and Autonomous AI Database endpoints run, including developer laptops and CI.
  • Assume the gateway holds secrets. LiteLLM proxies commonly hold provider keys; rotate and scope them, and give the service minimal egress so a shell has little to reach.
  • Do not open untrusted repositories or projects in Codex until a fix ships. The tested setup was stock Codex with its sandbox on, so the sandbox alone was not enough in the contest, and the allowed scenarios included an untrusted workspace before any trust prompt. Keep Codex away from production credentials on machines where you must.
  • Patch quickly once advisories appear. Watch ZDI's published advisories and each vendor's security pages, and update on release. Collisions mean some bugs were already known to a vendor, not that fixes exist.
  • Log and alert on unexpected child processes, outbound connections and admin API calls from these services.

Sources

Keep reading

All latest →
  1. highAI SecurityFake ChatGPT, Gemini, Claude and Muse ad portals use a fake browser window to steal ad-account logins7 min
  2. watchAI SecurityOpenAI Notified 100+ Organizations About Model Activity: A Notice Is Not a Compromise8 min
  3. highAI SecurityMCP TypeScript SDK Lets a Malicious Server Pull OAuth Secrets From Clients (CVE-2026-104850)4 min
  4. elevatedAI SecurityMistral Large 4 preview ships a reduced-moderation cyber tier, and Artificial Analysis lists its 82% as the top score6 min
  5. watchAI SecurityNextChat proxy fallback lets unauthenticated callers make the server fetch any URL (CVE-2026-105238)7 min
  6. highAI SecurityDify CVE-2026-105762: Unauthenticated SSRF in Remote-File Upload Reaches Internal Services and Cloud Metadata5 min