AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
MEDIUM CVE-2025-61914

n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this...

CVSS 5.4 n8n CWE-79
View details
HIGH CVE-2025-67729

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

CVSS 8.8 EPSS 0.1% CWE-502
View details
CRITICAL CVE-2025-68665

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection...

CVSS 9.1 langchain.js
View details
HIGH CVE-2025-68664

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd()...

CVSS 8.2 EPSS 0.0% langchain_core CWE-502
View details
UNKNOWN CVE-2025-14930

Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

transformers CWE-502
View details
UNKNOWN CVE-2025-14929

Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on...

transformers CWE-502
View details
UNKNOWN CVE-2025-14928

Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

transformers CWE-94
View details
UNKNOWN CVE-2025-14927

Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

transformers CWE-94
View details
UNKNOWN CVE-2025-14926

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

transformers CWE-94
View details
UNKNOWN CVE-2025-14924

Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

transformers CWE-502
View details
UNKNOWN CVE-2025-14921

Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

transformers CWE-502
View details
UNKNOWN CVE-2025-14920

Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

transformers CWE-502
View details
MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 EPSS 0.0% CWE-918
View details
HIGH ACTIVELY EXPLOITED CVE-2025-68613

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their...

CVSS 8.8 n8n CWE-913
View details
HIGH CVE-2025-68478

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the...

CVSS 7.1 EPSS 0.1% langflow CWE-73
View details
MEDIUM CVE-2025-68477

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component that can issue arbitrary HTTP requests within a flow....

CVSS 6.5 EPSS 0.0% langflow CWE-918
View details
HIGH CVE-2025-53000

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

EPSS 0.0% CWE-427
View details
MEDIUM CVE-2025-63390

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote...

CVSS 5.3
View details
CRITICAL CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring...

CVSS 9.8 ollama
View details
HIGH CVE-2025-67748

Fickling has Code Injection vulnerability via pty.spawn()

EPSS 0.0% fickling Patch: 0.1.6 CWE-94
View details
HIGH CVE-2025-67747

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

EPSS 0.1% fickling Patch: 0.1.6 CWE-184
View details
CRITICAL CVE-2025-67511

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the...

CVSS 9.6 EPSS 0.2% CWE-77
View details
HIGH CVE-2025-67644

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

CVSS 7.3 EPSS 0.0% CWE-89
View details
HIGH CVE-2025-33213

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to...

CVSS 8.8 CWE-502
View details
HIGH CVE-2025-65964

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation...

CVSS 8.8 n8n
View details
MEDIUM CVE-2025-13922

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview...

CVSS 6.5
View details
HIGH CVE-2025-34291

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with...

CVSS 8.8 EPSS 13.1% langflow CWE-346
View details
HIGH CVE-2025-65958

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

CVSS 8.5 EPSS 0.0% open-webui Patch: 0.6.37 CWE-918
View details
UNKNOWN CVE-2025-66479

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16,...

View details
LOW CVE-2025-63681

open-webui is Vulnerable to Incorrect Access Control

EPSS 0.0% open-webui CWE-284
View details
HIGH CVE-2025-66404

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes...

CVSS 8.8
View details
MEDIUM CVE-2025-13359

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and...

CVSS 6.5
View details
MEDIUM CVE-2025-13354

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin...

CVSS 4.3
View details
HIGH CVE-2025-66448

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm...

CVSS 8.8 EPSS 0.2% vllm CWE-94
View details
UNKNOWN CVE-2025-12638

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses Python's...

View details
CRITICAL CVE-2025-34351

Ray's New Token Authentication is Disabled By Default

EPSS 0.5% ray CWE-304
View details
CRITICAL CVE-2025-62593

Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack

EPSS 0.0% ray Patch: 2.52.0 CWE-94
View details
HIGH CVE-2025-65106

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template...

EPSS 0.1% langchain-core Patch: 1.0.7 CWE-1336
View details
HIGH CVE-2025-62609

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer...

CVSS 7.5 EPSS 0.1% mlx CWE-476
View details
CRITICAL CVE-2025-62608

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files....

CVSS 9.1 EPSS 0.1% mlx CWE-122
View details
HIGH CVE-2025-12973

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function...

CVSS 7.2
View details
MEDIUM CVE-2025-62426

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request...

CVSS 6.5 EPSS 0.1% vllm CWE-770
View details
MEDIUM CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal...

CVSS 6.5 EPSS 0.1% vllm CWE-129
View details
HIGH CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and...

CVSS 8.8 EPSS 0.1% vllm CWE-20
View details
LOW CVE-2025-63396

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service...

CVSS 3.3 pytorch
View details
MEDIUM CVE-2025-12732

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting()...

CVSS 4.3
View details
MEDIUM CVE-2025-11972

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due...

CVSS 4.9
View details
HIGH CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

CVSS 7.3 EPSS 0.2% open-webui Patch: 0.6.35 CWE-95
View details
HIGH CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

CVSS 8.7 EPSS 0.0% open-webui Patch: 0.6.35 CWE-79
View details
MEDIUM CVE-2025-12360

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up...

CVSS 4.3
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial