AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 973 results — no patch
MEDIUM CVE-2025-3933

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-6716

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 6.4
View details
MEDIUM CVE-2025-7021

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login...

CVSS 6.5 operator
View details
MEDIUM CVE-2025-6210

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

CVSS 6.2 EPSS 0.0% CWE-22
View details
HIGH CVE-2025-6386

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

CVSS 7.5 EPSS 0.1% lollms CWE-203
View details
MEDIUM CVE-2025-3044

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

CVSS 5.3 EPSS 0.1% CWE-440
View details
HIGH CVE-2025-3225

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVSS 7.5 EPSS 0.1% CWE-776
View details
HIGH CVE-2025-3046

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

CVSS 7.5 EPSS 0.1% CWE-22
View details
LOW CVE-2025-3777

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using...

CVSS 3.5 EPSS 0.0% transformers CWE-20
View details
MEDIUM CVE-2025-3264

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-3263

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
HIGH CVE-2025-3262

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-52554

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow...

CVSS 4.3 n8n
View details
MEDIUM CVE-2025-45809

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

CVSS 5.4 litellm
View details
MEDIUM CVE-2025-49595

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or...

CVSS 4.9 n8n
View details
UNKNOWN CVE-2025-34072

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes...

View details
HIGH CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation...

CVSS 8.8 EPSS 0.2% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-6854

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The...

CVSS 4.3 EPSS 0.1% langchain-chatchat CWE-22
View details
CRITICAL CVE-2025-6853

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the...

CVSS 9.8 EPSS 0.2% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains...

CVSS 5.4 n8n
View details
CRITICAL CVE-2025-53002

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training...

CVSS 9.8 EPSS 1.6% llamafactory CWE-94
View details
CRITICAL CVE-2025-2828

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically,...

CVSS 10.0 EPSS 0.1% langchain CWE-918
View details
HIGH CVE-2025-5018

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and...

CVSS 7.1
View details
HIGH CVE-2025-30167

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS 7.3 EPSS 0.0% CWE-427
View details
MEDIUM CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to...

CVSS 6.5 EPSS 0.1% vllm CWE-20
View details
MEDIUM CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48887

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file...

CVSS 6.5 EPSS 0.1% vllm CWE-1333
View details
HIGH CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an...

CVSS 7.5 EPSS 0.9% gradio CWE-434
View details
HIGH CVE-2025-46722

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a...

CVSS 7.3 EPSS 0.1% vllm CWE-1023
View details
LOW CVE-2025-46570

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the...

CVSS 2.6 EPSS 0.1% vllm CWE-203
View details
LOW CVE-2025-5320

A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument...

CVSS 3.7 EPSS 0.0% gradio CWE-345
View details
HIGH CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load...

CVSS 7.8 EPSS 0.1% CWE-502
View details
CRITICAL CVE-2025-47277

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer...

CVSS 9.8 EPSS 0.9% vllm CWE-502
View details
HIGH CVE-2025-2099

A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS)...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
UNKNOWN CVE-2025-1975

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to...

ollama
View details
HIGH CVE-2025-0649

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVSS 7.5 tensorflow_serving CWE-787
View details
HIGH CVE-2025-30165

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM...

CVSS 8.0 EPSS 1.3% vllm CWE-502
View details
LOW CVE-2025-4287

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation...

CVSS 3.3
View details
HIGH CVE-2025-46560

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input...

CVSS 7.5 EPSS 0.6% vllm CWE-1333
View details
CRITICAL CVE-2025-32444

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote...

CVSS 9.8 EPSS 2.5% vllm CWE-502
View details
HIGH CVE-2025-30202

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ...

CVSS 7.5 EPSS 0.4% vllm CWE-770
View details
MEDIUM CVE-2025-1194

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the...

CVSS 6.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-46343

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary...

CVSS 5.4 n8n
View details
CRITICAL CVE-2025-32434

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command...

CVSS 9.8 EPSS 1.2% pytorch CWE-502
View details
MEDIUM CVE-2025-3730

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation...

CVSS 5.5 EPSS 0.1% pytorch CWE-404
View details
CRITICAL CVE-2025-32428

TigerVNC accessible via the network and not just via a UNIX socket as intended

EPSS 0.2% CWE-668
View details
CRITICAL CVE-2025-32375

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting...

CVSS 9.8 EPSS 67.3% bentoml CWE-502
View details
CRITICAL ACTIVELY EXPLOITED CVE-2025-3248

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary...

CVSS 9.8 EPSS 92.5% langflow CWE-94
View details
CRITICAL CVE-2025-27520

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been...

CVSS 9.8 EPSS 87.3% bentoml CWE-502
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial