Researchers exploited a critical CI/CD vulnerability in PyTorch, a leading ML platform, by using a self-hosted GitHub runner to gain access to the repository and potentially modify its code. The vulnerability allowed them to upload malicious releases to GitHub and AWS, and add code to the main repository branch. The researchers reported the issue to PyTorch and received a $5,000 bug bounty. The exploit highlights the risks of supply chain attacks in the AI/ML industry.