Alternative theories, since OpenAI does not release proper information:
The cache proxy was from Astral (acquired by OpenAI) and the model was used for coding it, so it knew the code base and exploit already!
Or it was squid with dozens of known exploits ...
That is not really how LLMs work