I expect it must have been more than just an open redirect if it let the models then go on to execute a bunch of vulnerabilities against Hugging Face.
I wonder if it was this bug fixed july 14 in sonatype:
https://support.sonatype.com/hc/en-us/articles/5316501964136...
pure speculation here - no non public info
If it lets you do an arbitrary HTTP GET on a URL sent as a parameter to the main URL, you've escaped the sandbox rules.