Trend Micro Zero Day Initiative ran day 1 of Pwn2Own Ireland 2026 in Cork on October 7, 2026. Researchers demonstrated 32 previously unknown vulnerabilities across a range of target categories, earning $388,500 in total payouts. Two AI tooling targets attracted particular attention: LiteLLM, the open-source LLM proxy widely deployed in enterprise AI platforms, and OpenAI Codex, a developer-facing AI coding agent. Both were compromised by professional researchers using novel techniques.
LiteLLM: Path-traversal plus unsafe deserialization
LiteLLM is an open-source gateway that proxies requests to multiple LLM providers behind a unified API. Many enterprise AI platforms and internal copilot deployments run LiteLLM as their central routing layer. The Pwn2Own researcher exploited a path-traversal flaw in the model loading API that allowed arbitrary file access on the server. Combined with an unsafe deserialization gadget reachable through that file access path, the chain produced full remote code execution on the container hosting the proxy. The researcher then pivoted from model configuration access to host network access, escalating the impact beyond the initially compromised container.
OpenAI Codex: Single argument-injection
OpenAI Codex is a developer AI agent designed to accept a repository reference and autonomously perform coding tasks. The Pwn2Own researcher identified that Codex does not sufficiently sanitize the repository URL passed to its --repo flag before initiating the repository clone phase. By passing a crafted URL containing argument-injection payloads, the researcher caused Codex to execute attacker-controlled shell commands during the clone operation, before the agent had begun any task the developer requested. The bug demonstrates that AI agents accepting user-controlled external resource identifiers face a class of injection risk analogous to command injection in traditional software.
What this means for AI security teams
Pwn2Own targets are selected by professional researchers who spend months identifying high-value attack surfaces. The selection of LiteLLM and OpenAI Codex as explicit targets signals that the research community now regards AI tooling as comparable in attack-surface value to traditional network devices and browsers. Treating AI infrastructure as lower-priority than perimeter devices is no longer defensible.
- Apply LiteLLM updates as soon as patches are released. Monitor the LiteLLM GitHub repository for a security advisory addressing the Pwn2Own findings.
- Restrict network access to LiteLLM management and model-loading APIs. The proxy should not expose its administrative endpoints to untrusted network segments.
- Treat AI agent processes as untrusted code execution environments. Sandbox agent processes with least-privilege OS permissions and block outbound network from agents that do not require it.
- Review any developer tooling that accepts user-controlled or repository-controlled resource identifiers. Validate and sanitize these inputs the same way you would validate inputs in a web application.
Day 2 outlook
Day 2 results from Pwn2Own Ireland 2026 are expected on October 9. ZDI has not pre-announced additional AI targets, but further AI tooling exploits are plausible given the researcher interest demonstrated on day 1.
Gigia Tsiklauri is the founder of Infosec.ge, a cybersecurity intelligence platform covering the South Caucasus and Central Asia. Get in touch to submit a tip or discuss a story.