AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 524 results — High severity CVE-2026-22773 vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3...
CVE-2026-22612 Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22609 Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22608 Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22607 Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22606 Fickling has a bypass via runpy.run_path() and runpy.run_module()
GHSA-mcmc-2m55-j8jj vLLM introduced enhanced protection for CVE-2025-62164
GHSA-9726-w42j-3qjr picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-0621 Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded...
GHSA-46h3-79wf-xr6c Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
GHSA-955r-x9j8-7rhh Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
GHSA-rrxm-2pvv-m66x Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
GHSA-3329-ghmp-jmv5 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-x843-g5mx-g377 Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
GHSA-r8g5-cgf2-4m4m Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
GHSA-hgrh-qx5j-jfwx Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-vqmv-47xg-9wpr Picklescan missing detection when calling pty.spawn
GHSA-84r2-jw7c-4r5q Picklescan has Incomplete List of Disallowed Inputs
GHSA-4675-36f9-wf6r Picklescan does not block ctypes
GHSA-m273-6v24-x4m4 Picklescan vulnerable to Arbitrary File Writing
CVE-2025-67729 lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
CVE-2025-68664 LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd()...
CVE-2025-68613 n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their...
CVE-2025-68478 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the...
CVE-2025-53000 nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
CVE-2025-67748 Fickling has Code Injection vulnerability via pty.spawn()
CVE-2025-67747 Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
CVE-2025-67644 LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
CVE-2025-33213 NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to...
CVE-2025-65964 n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation...
CVE-2025-34291 Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with...
CVE-2025-65958 Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2025-66404 MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes...
CVE-2025-66448 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm...
CVE-2025-65106 LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template...
CVE-2025-62609 MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer...
CVE-2025-12973 The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function...
CVE-2025-62164 vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and...
CVE-2025-64496 Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2025-64439 LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
CVE-2025-62726 n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n....
CVE-2025-64104 LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
CVE-2025-8709 A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10....
CVE-2025-7707 llama-index has Insecure Temporary File
CVE-2025-6242 A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and...
CVE-2025-61784 LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the...
CVE-2025-59425 vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing...
CVE-2025-6985 The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class...
CVE-2025-7647 llama-index-core insecurely handles temporary files
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial