Pwn2Own Ireland 2026: LiteLLM, Codex, Chroma hacked
Pwn2Own Ireland 2026 broke LiteLLM, OpenAI Codex, Chroma and NVIDIA Dynamo. Vendors have 90 days to patch. Here is how to cut your AI stack's exposure now.
The AI tools small teams run every day just got broken on stage. At Pwn2Own Ireland 2026, researchers took over LiteLLM, OpenAI Codex, the Chroma vector database and NVIDIA Dynamo in the contest's AI infrastructure category. The bugs are now with the vendors. Patches come later. Your exposure is what you control today.
What actually happened
Per the Zero Day Initiative's Day One results:
- LiteLLM: Taisic Yun of Xint chained improper input validation with code injection for a working exploit, and won $40,000. A second team, Out of Bounds, also got in with a four-bug chain, though two of those bugs were already known. They won $15,000.
- OpenAI Codex: Ikotas Labs needed one argument-injection bug to exploit the coding agent. Prize: $40,000.
- Chroma: VinSOC ran out of time on Day One.
Day Two went worse for the AI stack. Out of Bounds took $40,000 for an exploit against Dynamo. Two of three teams got into Chroma, with a mix of new and already-known bugs. Two teams also broke the Oracle Autonomous AI Database.
BleepingComputer counted 32 zero-days on Day One alone, across all categories. Under Pwn2Own rules, vendors get 90 days to ship fixes before ZDI publishes details. Exploit specifics are not public yet, and we will not guess at them.
Why it matters for your business
Your AI gateway holds the keys. LiteLLM is the proxy many teams put in front of OpenAI, Anthropic and Google. It stores every provider API key you own. A takeover there is not one leak. It is all of them. This is not LiteLLM's first bad month either. We have covered its MCP auth bypass and its PyPI supply-chain compromise.
Vector databases are not internal by default. Chroma often ships in a quick RAG prototype with no auth and an open port. That prototype then quietly becomes production, full of customer documents.
Coding agents run with your permissions. One argument injection was enough for Codex. An agent that can run git and shell commands on your repo is a privileged user. Treat it like one.
What to do this week, before any patch:
- Keep LiteLLM, Chroma and inference servers off the public internet. Put them behind a VPN or a private network.
- Turn on authentication everywhere it exists. Chroma and LiteLLM both support it.
- Give each provider key a spend cap, and know how to rotate all of them in one hour.
- Run AI services as non-root users in their own containers.
- Watch the LiteLLM, Chroma and Codex release notes over the next 90 days, and patch the same day a fix lands.
Key takeaways
- Pwn2Own Ireland 2026 broke LiteLLM, OpenAI Codex, Chroma and NVIDIA Dynamo
- Vendors have 90 days to patch; exploit details are not public yet
- LiteLLM holds every provider key you route through it, so a takeover is a total key leak
- Get gateways and vector databases off the public internet and turn on auth now
- Treat coding agents as privileged users, not as autocomplete
Not sure what your AI stack exposes? We build AI systems with private networking, scoped keys, spend caps and a written inventory of every service, so a Pwn2Own result is a patch ticket, not an incident. See how we build it, or send us your stack for a review.
Sources: Zero Day Initiative, Day One, Zero Day Initiative, Day Two, BleepingComputer.
- #pwn2own
- #litellm
- #chroma
- #ai-security
- #self-hosted-llm
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
LMCache CVE-2026-105192: unpatched RCE in self-hosted LLMs
LMCache CVE-2026-105192 (CVSS 9.8) lets one network message run code on self-hosted LLM servers. No patch yet. Check your bind address and port 5555 today.
Read itNew Relic AI Evaluation: score the transaction, not the call
New Relic AI Evaluation hits public preview in November with guardrail checks, RAG scoring, and cost-to-quality views. Build your golden dataset first.
Read it