AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 524 results — High severity
HIGH CVE-2025-55560

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55559

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS 7.5 tensorflow
View details
HIGH CVE-2025-55558

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a...

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55557

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55553

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55552

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

CVSS 7.5 pytorch CWE-190
View details
HIGH CVE-2025-55551

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

CVSS 7.5 pytorch
View details
HIGH CVE-2025-6921

The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the...

CVSS 7.5 EPSS 0.0% transformers CWE-400
View details
HIGH CVE-2025-9906

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .keras model archive that, when loaded via...

CVSS 7.3 EPSS 0.1% keras CWE-502
View details
HIGH CVE-2025-9905

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via...

CVSS 7.3 EPSS 0.0% keras CWE-913
View details
HIGH CVE-2025-10155

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by...

CVSS 7.8 EPSS 0.0% picklescan CWE-20
View details
HIGH CVE-2025-6638

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method....

CVSS 7.5 EPSS 0.0% transformers CWE-1333
View details
HIGH CVE-2025-10156

Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

CVSS 7.5 EPSS 0.4% picklescan Patch: 0.0.31 CWE-693
View details
HIGH CVE-2025-10157

Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports

CVSS 8.3 EPSS 0.1% picklescan Patch: 0.0.31 CWE-693
View details
HIGH CVE-2025-58757

Monai: Unsafe use of Pickle deserialization may lead to RCE

CVSS 8.8 EPSS 0.6% monai Patch: 1.5.1 CWE-502
View details
HIGH CVE-2025-58756

MONAI: Unsafe torch usage may lead to arbitrary code execution

CVSS 8.8 EPSS 1.2% monai Patch: 1.5.1 CWE-502
View details
HIGH CVE-2025-58755

MONAI does not prevent path traversal, potentially leading to arbitrary file writes

CVSS 8.8 EPSS 0.1% monai Patch: 1.5.1 CWE-22
View details
HIGH CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVSS 8.8 n8n
View details
HIGH CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The...

CVSS 7.5 EPSS 2.1% langchain-community Patch: 0.3.27 CWE-200
View details
HIGH CVE-2025-5302

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

CVSS 8.6 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
HIGH CVE-2025-57809

XGrammar affected by Denial of Service by infinite recursion grammars

CVSS 7.5 EPSS 0.0% xgrammar Patch: 0.1.21 CWE-674
View details
HIGH CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can...

CVSS 8.8 EPSS 0.0% langflow CWE-269
View details
HIGH CVE-2025-48956

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request...

CVSS 7.5 EPSS 0.4% vllm CWE-400
View details
HIGH CVE-2025-9141

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

CVSS 8.8 vllm Patch: 0.10.1.1 CWE-502
View details
HIGH CVE-2025-23298

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability...

CVSS 7.8
View details
HIGH GHSA-9gvj-pp9x-gcfr

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

picklescan Patch: 0.0.27 CWE-502
View details
HIGH CVE-2025-8747

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a...

CVSS 7.8 EPSS 0.0% keras CWE-502
View details
HIGH CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code...

CVSS 8.4 EPSS 0.3% CWE-502
View details
HIGH CVE-2025-7725

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 7.2
View details
HIGH CVE-2025-54413

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which can be exploited to access...

EPSS 0.0% CWE-351
View details
HIGH CVE-2025-54412

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide...

EPSS 0.0% CWE-351
View details
HIGH CVE-2025-30402

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

CVSS 8.1 EPSS 0.1% executorch Patch: 0.7.0-rc1 CWE-122
View details
HIGH CVE-2025-6209

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS 7.5 EPSS 0.1% llama-index-core Patch: 0.12.41 CWE-29
View details
HIGH CVE-2025-6386

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

CVSS 7.5 EPSS 0.1% lollms CWE-203
View details
HIGH CVE-2025-3046

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

CVSS 7.5 EPSS 0.1% CWE-22
View details
HIGH CVE-2025-3225

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVSS 7.5 EPSS 0.1% CWE-776
View details
HIGH CVE-2025-3262

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
HIGH CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation...

CVSS 8.8 EPSS 0.2% langchain-chatchat CWE-22
View details
HIGH CVE-2025-5018

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and...

CVSS 7.1
View details
HIGH CVE-2025-30167

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS 7.3 EPSS 0.0% CWE-427
View details
HIGH CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an...

CVSS 7.5 EPSS 0.9% gradio CWE-434
View details
HIGH CVE-2025-46722

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a...

CVSS 7.3 EPSS 0.1% vllm CWE-1023
View details
HIGH CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load...

CVSS 7.8 EPSS 0.1% CWE-502
View details
HIGH CVE-2025-2099

A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS)...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
HIGH CVE-2025-47783

label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

EPSS 0.2% label-studio Patch: 1.18.0 CWE-79
View details
HIGH CVE-2025-1752

LlamaIndex Vulnerable to Denial of Service (DoS)

CVSS 7.5 EPSS 0.2% llama-index Patch: 0.12.21 CWE-400
View details
HIGH CVE-2025-0649

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVSS 7.5 tensorflow_serving CWE-787
View details
HIGH CVE-2025-30165

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM...

CVSS 8.0 EPSS 1.3% vllm CWE-502
View details
HIGH CVE-2025-46567

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script...

CVSS 7.8 EPSS 0.2% llamafactory Patch: 0.9.3 CWE-502
View details
HIGH CVE-2025-46560

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input...

CVSS 7.5 EPSS 0.6% vllm CWE-1333
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial