One Argument Injection Beat Codex; Oracle’s AI Database Took a Seven-Bug Chain — Pwn2Own Ireland’s AI Track

Pwn2Own Ireland 2026 opened in Cork on 6 October with more than 60 entries, and for the first time the schedule carries a standalone Coding Agent category alongside AI Infrastructure. Day three is still running as we publish, so the final leaderboard is not settled. The first two days are settled, and they say something precise about where the cheap bugs are.

Eleven of the scheduled attempts across days one and two targeted AI software: LiteLLM, Chroma, NVIDIA Dynamo and Oracle Autonomous AI Database in AI Infrastructure, plus OpenAI Codex in Coding Agent. Nine of the eleven landed. Together they paid $215,500 — of the $388,500 ZDI awarded on day one, $135,000 came from the AI track alone.

The cost asymmetry

The two headline results from day one sit at opposite ends of the exploitation-cost curve, and they were demonstrated roughly two hours apart.

At 4:15 PM, VinSOC — Nam Nguyen, Thanh Vu and Tin Huynh — combined five bugs to take the Oracle Autonomous AI Database for the full $40,000. At 6:00 PM, Ikotas Labs used a single argument injection bug to exploit OpenAI Codex, also for $40,000. ZDI’s write-up of the Codex demo is one sentence long, because there is only one bug in it.

That is the same primitive class we covered when AWS shipped a fix in August and the advisory in October for CVE-2026-97662, where a Git ref flowed into a command line and became a file write. Argument injection keeps surfacing in agent tooling for a structural reason: a coding agent’s entire job is to assemble argument vectors for other programs from text it did not write. A traditional database has to be reached through a network stack, a parser and a privilege boundary — hence five bugs, then seven. An agent exposes the command line as a feature.

Oracle’s target absorbed three separate rounds over two days and got progressively more expensive to break, exactly as a hardened product should:

  • Round one (day one) — VinSOC, 5 bugs, $40,000 and 4 Master of Pwn points.
  • Round two (day two) — Taisic Yun of Xint, 3 collisions and 2 unique zero-days, net $14,000 and 3 points.
  • Round three (day two) — Ikotas Labs, a seven-bug chain ending in a use-after-free and a type confusion, $10,000 and 4 points.

The declining cash is contest mechanics, not a judgement on the research: Pwn2Own pays the full pot to the first successful demo against a target and discounts subsequent rounds. ZDI states the rule plainly elsewhere in the same posts — McCaulay Hudson’s Canon imageFORCE win is described as a “2nd round win” netting $10,000 against a $20,000 target, and Sina Kheirkhah’s Lexmark result on day one is described the same way. Seven chained bugs for a third-round $10,000 is the single most expensive piece of work on the AI track.

The collision rate is the uncomfortable number

A “collision” at Pwn2Own means the bug was already known to the vendor or already public. Four of the nine successful AI-track demos were discounted for collisions or N-days:

  • LiteLLM — Out of Bounds (HaeJung Yang, ByungYoung Yi) used 4 bugs, 2 previously known. Net $15,000.
  • Oracle Autonomous AI Database — Xint, 3 of 5 collisions. Net $14,000.
  • Chroma — Team MAMMOTH (seven researchers), 2 collisions and 1 zero-day. Net $12,000 but only 1.25 Master of Pwn points.
  • Chroma — Alessandro Fanio Gonzalez, 2 N-days and 1 collision. Net $4,500.

Read the last one again. ZDI describes Gonzalez’s successful exploit as containing two N-days — bugs that were already publicly disclosed — and a collision. A competition-grade exploit against a widely deployed vector database, assembled in October 2026 partly out of material that was already in public. We wrote about an unpatched ChromaDB RCE in May; the contest result suggests the gap between “disclosed” and “not reachable anymore” in this corner of the stack is still wide enough to drive an exploit chain through.

Chroma was also the hardest target to hit cleanly. Two teams failed on it outright — VinSOC ran out of time on day one, and Eugene (@k3vg3n) ran out of clock on day two with, in ZDI’s words, “seconds left.” The two teams that did succeed both did so with heavily discounted chains. That is not a picture of a robust target; it is a picture of a flaky one where the reliable bugs are already spoken for.

LiteLLM, again

LiteLLM drew two attempts and fell to both. Taisic Yun of Xint took the full $40,000 on the first, using an improper input validation bug plus code injection to land a reverse shell. Out of Bounds followed with a four-bug chain, half of it already known.

LiteLLM is now a recurring fixture here. It is the project whose MCP auth bypass became the first MCP flaw in CISA’s KEV catalog, and whose unverified-email-to-permanent-admin flaw was still unpatched at the end of September. Appearing as a Pwn2Own target at all is a sign of how central the AI gateway layer has become; falling twice in one morning is a sign that the target selection was correct.

NVIDIA Dynamo, new to the target list this year, fell once — HaeJung Yang of Out of Bounds, $40,000 and 4 points, with no collision recorded. ZDI has not published the bug class.

What defenders should take from this

  • Treat the Coding Agent category as a 90-day clock that has already started. ZDI disclosed the Codex bug to OpenAI under the standard contest terms; the bug class — argument injection — is public, the vendor is named, the affected versions are not. Until a fix ships, assume any Codex-equivalent agent that constructs shell arguments from repository or web content is reachable the same way.
  • Do not read the dollar figures as severity. The $10,000 seven-bug Oracle chain is harder research than the $40,000 single-bug Codex win. Pwn2Own prices novelty and ordering, not impact. For risk purposes, bug count is the better proxy: one bug means one mistake stands between an attacker and your agent.
  • Inventory the AI infrastructure tier as infrastructure. LiteLLM, Chroma, Dynamo and managed AI databases are now contest targets with named, time-boxed exploitation. They belong in the same patch cadence as your reverse proxies, not in a “new tooling” backlog. Several of these components are deployed by data teams outside the usual asset inventory.
  • Assume your vector database has public N-days you have not applied. The Chroma result is the direct evidence. Pull the changelog, not the advisory feed — not every fix in this ecosystem gets a CVE.
  • Watch for the CVEs, not the headlines. ZDI publishes contest results immediately and vulnerability details after vendor coordination. Last year’s equivalents, including the Codex exploitation at Pwn2Own Berlin in May, took months to surface as identifiers. Set a reminder rather than waiting for a notification.

Verification note: every result, researcher name, bug count, collision count, dollar figure and Master of Pwn score in this briefing was read directly from the Zero Day Initiative’s own day-one and day-two result posts and the published Pwn2Own Ireland 2026 schedule. The $388,500 day-one total and the “32 unique 0-days” figure are ZDI’s. The $215,500 and $135,000 AI-track subtotals are our arithmetic over ZDI’s per-attempt figures and are not published by ZDI. Day three was still in progress at the time of writing and is excluded. ZDI has not published bug classes, affected versions or CVE identifiers for any of these entries beyond the short descriptions quoted; where we have not quoted a mechanism, none was published. We tested nothing and exploited nothing.

Sources: