I don't know if the LLM was trained to test vulnerabilities or it just went down the statistical path to where this yielded a passing outcome.
That AI could take a direction to output in a manner which wasn't intended has been seen for years. The problem right now is that it is being used live like a rational human adult when it clearly isn't.