Skip to content
Rush Commerce
Software & Dev3 min read

Pwn2Own Ireland 2026: LiteLLM, Codex, Chroma hacked

Pwn2Own Ireland 2026 broke LiteLLM, OpenAI Codex, Chroma and NVIDIA Dynamo. Vendors have 90 days to patch. Here is how to cut your AI stack's exposure now.

The AI tools small teams run every day just got broken on stage. At Pwn2Own Ireland 2026, researchers took over LiteLLM, OpenAI Codex, the Chroma vector database and NVIDIA Dynamo in the contest's AI infrastructure category. The bugs are now with the vendors. Patches come later. Your exposure is what you control today.

What actually happened

Per the Zero Day Initiative's Day One results:

  • LiteLLM: Taisic Yun of Xint chained improper input validation with code injection for a working exploit, and won $40,000. A second team, Out of Bounds, also got in with a four-bug chain, though two of those bugs were already known. They won $15,000.
  • OpenAI Codex: Ikotas Labs needed one argument-injection bug to exploit the coding agent. Prize: $40,000.
  • Chroma: VinSOC ran out of time on Day One.

Day Two went worse for the AI stack. Out of Bounds took $40,000 for an exploit against Dynamo. Two of three teams got into Chroma, with a mix of new and already-known bugs. Two teams also broke the Oracle Autonomous AI Database.

BleepingComputer counted 32 zero-days on Day One alone, across all categories. Under Pwn2Own rules, vendors get 90 days to ship fixes before ZDI publishes details. Exploit specifics are not public yet, and we will not guess at them.

Why it matters for your business

Your AI gateway holds the keys. LiteLLM is the proxy many teams put in front of OpenAI, Anthropic and Google. It stores every provider API key you own. A takeover there is not one leak. It is all of them. This is not LiteLLM's first bad month either. We have covered its MCP auth bypass and its PyPI supply-chain compromise.

Vector databases are not internal by default. Chroma often ships in a quick RAG prototype with no auth and an open port. That prototype then quietly becomes production, full of customer documents.

Coding agents run with your permissions. One argument injection was enough for Codex. An agent that can run git and shell commands on your repo is a privileged user. Treat it like one.

What to do this week, before any patch:

  1. Keep LiteLLM, Chroma and inference servers off the public internet. Put them behind a VPN or a private network.
  2. Turn on authentication everywhere it exists. Chroma and LiteLLM both support it.
  3. Give each provider key a spend cap, and know how to rotate all of them in one hour.
  4. Run AI services as non-root users in their own containers.
  5. Watch the LiteLLM, Chroma and Codex release notes over the next 90 days, and patch the same day a fix lands.

Key takeaways

  • Pwn2Own Ireland 2026 broke LiteLLM, OpenAI Codex, Chroma and NVIDIA Dynamo
  • Vendors have 90 days to patch; exploit details are not public yet
  • LiteLLM holds every provider key you route through it, so a takeover is a total key leak
  • Get gateways and vector databases off the public internet and turn on auth now
  • Treat coding agents as privileged users, not as autocomplete

Not sure what your AI stack exposes? We build AI systems with private networking, scoped keys, spend caps and a written inventory of every service, so a Pwn2Own result is a patch ticket, not an incident. See how we build it, or send us your stack for a review.

Sources: Zero Day Initiative, Day One, Zero Day Initiative, Day Two, BleepingComputer.

  • #pwn2own
  • #litellm
  • #chroma
  • #ai-security
  • #self-hosted-llm
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.