Clearly there was a hole in the software but I don't think open redirect is the likely initial problem.
Hopefully we will find out for sure in a few days.
https://support.sonatype.com/hc/en-us/articles/5316501964136...
pure speculation here - no non public info
Firstly, they all credit named individuals who don't seem to have a relationship with OpenAI - this one credits e0x1337 for example and https://hackerone.com/e0x1337?type=user links to https://www.linkedin.com/in/aimanharith
Secondly, the 14th of July feels too early. HF reported the incident on the 16th and OpenAI only responded in the 21st. These issues are all patched, so they should have been reported days or weeks before the 14th.
I suspect it may be possible to throw a local model (same as hf did :D) at jfrog and find the exact mechanism in a small amount of hours.