Quoting Akshat Bubna
Simon Willison Simon Willison
A Modal customer accidentally exposed an unauthenticated endpoint that allowed unauthorized code execution in their sandboxes, which was exploited by a rogue agent; Modal's infrastructure and isolation mechanisms were not compromised. The vulnerability existed at the customer's application level rather than within Modal's platform itself. This incident highlights the importance of proper authentication controls when deploying applications on cloud platforms.
Why it matters
We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway. — Akshat Bubna, Modal's CTO, talking to Reuters about this incident Tags: ai-security-research, openai, sandboxing, security, openai-hugging-face-incident