AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 450 results — High severity, no patch
HIGH CVE-2025-64104

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

CVSS 7.3 EPSS 0.1% CWE-89
View details
HIGH CVE-2025-8709

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10....

CVSS 7.3 EPSS 0.0% CWE-89
View details
HIGH CVE-2025-59425

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing...

CVSS 7.5 EPSS 0.4% vllm CWE-385
View details
HIGH CVE-2025-6985

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class...

CVSS 7.5 EPSS 0.2% CWE-611
View details
HIGH CVE-2025-55560

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55559

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS 7.5 tensorflow
View details
HIGH CVE-2025-55558

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a...

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55557

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55553

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55552

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

CVSS 7.5 pytorch CWE-190
View details
HIGH CVE-2025-55551

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

CVSS 7.5 pytorch
View details
HIGH CVE-2025-6921

The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the...

CVSS 7.5 EPSS 0.0% transformers CWE-400
View details
HIGH CVE-2025-9906

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .keras model archive that, when loaded via...

CVSS 7.3 EPSS 0.1% keras CWE-502
View details
HIGH CVE-2025-9905

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via...

CVSS 7.3 EPSS 0.0% keras CWE-913
View details
HIGH CVE-2025-10155

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by...

CVSS 7.8 EPSS 0.0% picklescan CWE-20
View details
HIGH CVE-2025-6638

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method....

CVSS 7.5 EPSS 0.0% transformers CWE-1333
View details
HIGH CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVSS 8.8 n8n
View details
HIGH CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can...

CVSS 8.8 EPSS 0.0% langflow CWE-269
View details
HIGH CVE-2025-48956

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request...

CVSS 7.5 EPSS 0.4% vllm CWE-400
View details
HIGH CVE-2025-23298

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability...

CVSS 7.8
View details
HIGH CVE-2025-8747

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a...

CVSS 7.8 EPSS 0.0% keras CWE-502
View details
HIGH CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code...

CVSS 8.4 EPSS 0.3% CWE-502
View details
HIGH CVE-2025-7725

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 7.2
View details
HIGH CVE-2025-54413

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which can be exploited to access...

EPSS 0.0% CWE-351
View details
HIGH CVE-2025-54412

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide...

EPSS 0.0% CWE-351
View details
HIGH CVE-2025-6386

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

CVSS 7.5 EPSS 0.1% lollms CWE-203
View details
HIGH CVE-2025-3225

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVSS 7.5 EPSS 0.1% CWE-776
View details
HIGH CVE-2025-3046

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

CVSS 7.5 EPSS 0.1% CWE-22
View details
HIGH CVE-2025-3262

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
HIGH CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation...

CVSS 8.8 EPSS 0.2% langchain-chatchat CWE-22
View details
HIGH CVE-2025-5018

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and...

CVSS 7.1
View details
HIGH CVE-2025-30167

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS 7.3 EPSS 0.0% CWE-427
View details
HIGH CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an...

CVSS 7.5 EPSS 0.9% gradio CWE-434
View details
HIGH CVE-2025-46722

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a...

CVSS 7.3 EPSS 0.1% vllm CWE-1023
View details
HIGH CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load...

CVSS 7.8 EPSS 0.1% CWE-502
View details
HIGH CVE-2025-2099

A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS)...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
HIGH CVE-2025-0649

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVSS 7.5 tensorflow_serving CWE-787
View details
HIGH CVE-2025-30165

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM...

CVSS 8.0 EPSS 1.3% vllm CWE-502
View details
HIGH CVE-2025-46560

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input...

CVSS 7.5 EPSS 0.6% vllm CWE-1333
View details
HIGH CVE-2025-30202

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ...

CVSS 7.5 EPSS 0.4% vllm CWE-770
View details
HIGH CVE-2025-30370

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

CVSS 7.4 EPSS 0.1% CWE-78
View details
HIGH CVE-2025-30358

Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and...

CVSS 8.1 EPSS 3.1% CWE-915
View details
HIGH CVE-2025-0330

LiteLLM Has a Leakage of Langfuse API Keys

CVSS 7.5 EPSS 0.1% litellm CWE-1230
View details
HIGH GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

CVSS 7.5 open-webui CWE-400
View details
HIGH CVE-2024-8020

PyTorch Lightning denial of service vulnerability

CVSS 7.5 EPSS 0.1% pytorch-lightning CWE-248
View details
HIGH CVE-2024-7983

Open WebUI denial of service through endpoint for converting markdown

CVSS 7.5 EPSS 0.2% open-webui CWE-400
View details
HIGH CVE-2024-7990

Open WebUI stored cross-site scripting (XSS) vulnerability

CVSS 8.4 EPSS 0.2% open-webui CWE-79
View details
HIGH CVE-2024-8053

Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint

CVSS 7.5 EPSS 0.8% open-webui CWE-287
View details
HIGH CVE-2024-7053

Open WebUI Vulnerable to a Session Fixation Attack

CVSS 7.6 EPSS 0.2% open-webui CWE-79
View details
HIGH CVE-2024-6825

LiteLLM Vulnerable to Remote Code Execution (RCE)

CVSS 8.8 EPSS 1.3% litellm CWE-77
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial