AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 1140 results CVE-2026-0768 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not...
CVE-2025-15063 Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server....
CVE-2025-65098 Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a...
CVE-2026-22807 vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model...
CVE-2026-21852 Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before...
CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
CVE-2025-33233 NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution,...
CVE-2026-22219 Chainlit contain a server-side request forgery (SSRF) vulnerability
CVE-2026-0863 Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system....
CVE-2026-0897 Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component
CVE-2025-68492 Chainlit contains an authorization bypass vulnerability
CVE-2025-68949 n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a...
CVE-2025-15514 Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data...
CVE-2024-58340 LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method...
CVE-2024-58339 LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query()...
CVE-2024-14021 LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py....
CVE-2026-22033 Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
CVE-2025-14279 MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to...
CVE-2026-22773 vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3...
CVE-2026-22612 Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22609 Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22608 Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22607 Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22606 Fickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2025-14980 The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated...
GHSA-mcmc-2m55-j8jj vLLM introduced enhanced protection for CVE-2025-62164
GHSA-9726-w42j-3qjr picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-21894 n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to...
CVE-2026-21877 n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full...
CVE-2026-21858 n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based...
CVE-2026-21851 MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
CVE-2025-14371 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
CVE-2026-0621 Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded...
CVE-2026-21445 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue...
GHSA-46h3-79wf-xr6c Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
GHSA-955r-x9j8-7rhh Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
GHSA-6556-fwc2-fg2p Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
GHSA-rrxm-2pvv-m66x Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
GHSA-cffc-mxrf-mhh4 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
GHSA-3329-ghmp-jmv5 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-x843-g5mx-g377 Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
GHSA-r8g5-cgf2-4m4m Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
GHSA-hgrh-qx5j-jfwx Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-vqmv-47xg-9wpr Picklescan missing detection when calling pty.spawn
GHSA-84r2-jw7c-4r5q Picklescan has Incomplete List of Disallowed Inputs
GHSA-4675-36f9-wf6r Picklescan does not block ctypes
GHSA-m273-6v24-x4m4 Picklescan vulnerable to Arbitrary File Writing
CVE-2025-68697 n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated...
CVE-2025-68668 n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with...
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial