Skip to content

Security2 publishersIndependently confirmed2 min readPublished

LiteLLM and OpenAI Codex fall to injection bugs on Pwn2Own Ireland's first day

Pwn2Own Ireland teams logged 32 zero-days and over $368,000 in prizes on October 6, breaking LiteLLM, OpenAI Codex and Oracle's AI database. Vendors now have 90 days to ship fixes before the Zero Day Initiative publishes the details.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying LiteLLM and OpenAI Codex fall to injection bugs on Pwn2Own Ireland's first day
Generated illustration

What happened

  • Ikotas Labs exploited OpenAI Codex with a single argument injection bug.
  • Taisic Yun of Xint chained an improper input validation bug with code injection to get a reverse shell on LiteLLM.
  • Three VinSOC researchers combined five zero-days to exploit the Oracle Autonomous AI Database.
  • ZDI counted 21 day-one entries, including several Samsung attempts and what it called its first Pixel entry.
  • Ikotas Labs could not get its exploit of the Brother MFC-L8970CDW printer working in the time allotted.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A product name and a bug class are all LiteLLM and Codex users have until details publish, too little to scope affected versions or write detections.
  • precedent With AI tools in the target categories, their makers join phone and printer vendors on ZDI's coordinated-disclosure clock for every bug found at the contest.
  • contradiction The AI statistics paired with the results pull in opposite directions, with Google finding AI-found bugs skew to code execution and separate research finding few exploited, and neither set measures attacks on AI tools.

Both AI developer tools fell to injection-class bugs [5][6]. The hardware entries whose bug classes were published fell to memory-safety bugs [20]. @_McCaulay chained an out-of-bounds write with a format string bug on the Sonos Era 300 [9]. On the Garmin Index BPM, Interrupt Labs paired an out-of-bounds read with an out-of-bounds write [11]. Thanh Do of Team Confused needed one use-after-free for the Lexmark CX532adwe printer [10].

Bug count splits the field another way. Codex and the Lexmark each took one bug [5][10]. Two VinSOC researchers found seven zero-days on their way into the Philips Hue Bridge Pro [8].

AI software sat on the same day-one target list as smartphones, smart home devices and printers [2], and three AI products fell [19]. The record shows working exploits against named products under contest conditions. Neither report describes any of these bugs being used outside the contest.

ZDI discloses Pwn2Own findings to the affected vendors, who then have 90 days to release updates before ZDI publishes them [12]. Counted from October 6, the window closes on January 4, 2027 [22]. A vendor can ship sooner [12].

Infosecurity Magazine set the results beside Google figures on AI as a bug-finding tool [15]. According to Google, vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July, then reached 10,740 in August [13]. Exploited vulnerabilities rose from an average of 10.5 a month in 2025 to 18 a month so far in 2026, by the same count [14]. Half the bugs Google identified as likely AI-discovered led to remote code execution, against 26% of other CVEs [15]. Separate research cited by the magazine puts the share of AI-discovered bugs exploited in the wild at 1% [21].

The day-one purse averages at least $11,500 per zero-day [18].

What to watch

  • LiteLLM and OpenAI advisories naming affected versions and fixes, the first point at which operators can check their own exposure.
  • Results from October 7 and 8, including whether more AI targets fall before the Master of Pwn is named.
  • Any report of a day-one bug being exploited outside the contest before patches ship.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories