AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
HIGH CVE-2025-64439

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

EPSS 0.8% CWE-502
View details
MEDIUM CVE-2025-12695

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

CVSS 5.9 EPSS 0.0% CWE-653
View details
HIGH CVE-2025-62726

n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n....

CVSS 8.8 n8n
View details
CRITICAL CVE-2025-12060

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without...

CVSS 9.8 EPSS 0.1% keras Patch: 3.12.0 CWE-22
View details
LOW CVE-2025-50736

Byaidu PDFMathTranslate vulnerable to open redirect

EPSS 0.0% CWE-601
View details
HIGH CVE-2025-64104

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

CVSS 7.3 EPSS 0.1% CWE-89
View details
UNKNOWN CVE-2025-11203

LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM....

View details
CRITICAL CVE-2025-11201

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow...

CVSS 9.8 EPSS 9.1% mlflow CWE-22
View details
CRITICAL CVE-2025-11200

MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not...

CVSS 9.8 EPSS 0.2% mlflow CWE-521
View details
MEDIUM CVE-2025-12058

The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF)....

EPSS 0.1% keras Patch: 3.12.0 CWE-502
View details
HIGH CVE-2025-8709

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10....

CVSS 7.3 EPSS 0.0% CWE-89
View details
MEDIUM CVE-2025-11844

Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath...

CVSS 5.4 EPSS 0.0% smolagents CWE-643
View details
MEDIUM CVE-2025-60511

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in...

CVSS 4.3
View details
CRITICAL CVE-2025-49655

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing a...

CVSS 9.8 EPSS 0.0% keras Patch: 3.11.3 CWE-502
View details
HIGH CVE-2025-7707

llama-index has Insecure Temporary File

CVSS 7.1 EPSS 0.0% llama-index Patch: 0.13.0 CWE-377
View details
CRITICAL GHSA-m9mp-6x32-5rhg

scio is vunerable to Remote Command Execution through PyTorch

CWE-502
View details
MEDIUM CVE-2025-61620

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

CVSS 6.5 vllm Patch: 0.11.0 CWE-20
View details
HIGH CVE-2025-6242

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and...

CVSS 7.1 EPSS 0.0% vllm Patch: 0.11.0 CWE-601
View details
HIGH CVE-2025-61784

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the...

CVSS 8.1 EPSS 0.1% llamafactory Patch: 0.9.4 CWE-918
View details
HIGH CVE-2025-59425

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing...

CVSS 7.5 EPSS 0.4% vllm CWE-385
View details
HIGH CVE-2025-6985

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class...

CVSS 7.5 EPSS 0.2% CWE-611
View details
MEDIUM CVE-2025-8917

clearml is vulnerable to Path Traversal through its `safe_extract` function

CVSS 5.8 EPSS 0.0% clearml Patch: 2.0.2 CWE-22
View details
HIGH CVE-2025-7647

llama-index-core insecurely handles temporary files

CVSS 7.3 EPSS 0.0% llama-index-core Patch: 0.13.0 CWE-378
View details
LOW CVE-2025-59842

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

EPSS 0.0% CWE-1022
View details
HIGH CVE-2025-55560

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55559

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVSS 7.5 tensorflow
View details
HIGH CVE-2025-55558

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a...

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55557

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
MEDIUM CVE-2025-55556

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVSS 6.5 tensorflow
View details
MEDIUM CVE-2025-55554

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

CVSS 5.3 pytorch
View details
HIGH CVE-2025-55553

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 pytorch
View details
HIGH CVE-2025-55552

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

CVSS 7.5 pytorch CWE-190
View details
HIGH CVE-2025-55551

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

CVSS 7.5 pytorch
View details
MEDIUM CVE-2025-46153

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d,...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46152

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46150

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46149

In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46148

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

CVSS 5.3 pytorch
View details
HIGH CVE-2025-6921

The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the...

CVSS 7.5 EPSS 0.0% transformers CWE-400
View details
UNKNOWN CVE-2025-59532

Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s...

View details
CRITICAL CVE-2025-59434

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on...

CVSS 9.6
View details
HIGH CVE-2025-9906

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .keras model archive that, when loaded via...

CVSS 7.3 EPSS 0.1% keras CWE-502
View details
HIGH CVE-2025-9905

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, when loaded via...

CVSS 7.3 EPSS 0.0% keras CWE-913
View details
HIGH CVE-2025-10155

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by...

CVSS 7.8 EPSS 0.0% picklescan CWE-20
View details
MEDIUM CVE-2025-58177

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-6051

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer`...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
CRITICAL CVE-2025-9556

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a...

CVSS 9.8
View details
HIGH CVE-2025-6638

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method....

CVSS 7.5 EPSS 0.0% transformers CWE-1333
View details
HIGH CVE-2025-10156

Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

CVSS 7.5 EPSS 0.4% picklescan Patch: 0.0.31 CWE-693
View details
HIGH CVE-2025-10157

Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports

CVSS 8.3 EPSS 0.1% picklescan Patch: 0.0.31 CWE-693
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial