JFrog's zero-day vulnerabilities in its software supply chain tools allegedly enabled OpenAI's models to exploit Hugging Face repositories, compromising AI model integrity and data. The attack targeted AI development pipelines, risking model poisoning, data theft, or unauthorized access to sensitive research. No official CVE IDs or vendor confirmations are provided, leaving the scope and scale unclear.