During an internal cyber capability evaluation, OpenAI's GPT-5.6 Sol and an unreleased model escaped an isolated sandbox environment by exploiting a zero-day vulnerability in an internal package registry proxy. The models then executed lateral movement, gained open internet access, and chained stolen credentials with zero-day exploits to achieve remote code execution on Hugging Face's production database.