AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
HIGH CVE-2025-58757

Monai: Unsafe use of Pickle deserialization may lead to RCE

CVSS 8.8 EPSS 0.6% monai Patch: 1.5.1 CWE-502
View details
HIGH CVE-2025-58756

MONAI: Unsafe torch usage may lead to arbitrary code execution

CVSS 8.8 EPSS 1.2% monai Patch: 1.5.1 CWE-502
View details
HIGH CVE-2025-58755

MONAI does not prevent path traversal, potentially leading to arbitrary file writes

CVSS 8.8 EPSS 0.1% monai Patch: 1.5.1 CWE-22
View details
HIGH CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVSS 8.8 n8n
View details
MEDIUM CVE-2025-58446

xgrammar vulnerable to denial of service by huge enum grammar

EPSS 0.1% xgrammar Patch: 0.1.24 CWE-770
View details
HIGH CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The...

CVSS 7.5 EPSS 2.1% langchain-community Patch: 0.3.27 CWE-200
View details
MEDIUM GHSA-q77w-mwjj-7mqx

Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-49gj-c84q-6qm9

Picklescan is missing detection when calling built-in python cProfile.run

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-9w88-8rmg-7g2p

Picklescan is missing detection when calling built-in python cProfile.runctx

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-fqq6-7vqf-w3fg

Picklescan is missing detection when calling built-in python doctest.debug_script

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-3gf5-cxq9-w223

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-j343-8v2j-ff7w

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-m869-42cg-3xwr

Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-p9w7-82w4-7q8m

Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-xp4f-hrf8-rxw7

Picklescan is missing detection when calling built-in python ensurepip._run_pip

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-4whj-rm5r-c2v8

Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-9xph-j2h6-g47v

Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-8r4j-24qv-fmq9

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-cj3c-v495-4xqh

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-7cq8-mj8x-j263

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-6w4w-5w54-rjvr

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-3vg9-h568-4w9m

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-f54q-57x4-jg88

Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-6vqj-c2q5-j97w

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-x696-vm39-cp64

Picklescan has a missing detection when calling built-in python profile.Profile.run

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-g344-hcph-8vgg

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-5qwp-399c-mjwf

Picklescan has a missing detection when calling built-in python trace.Trace.run

picklescan Patch: 0.0.29
View details
CRITICAL CVE-2025-55526

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

CVSS 9.1 fastapi
View details
HIGH CVE-2025-5302

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

CVSS 8.6 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
HIGH CVE-2025-57809

XGrammar affected by Denial of Service by infinite recursion grammars

CVSS 7.5 EPSS 0.0% xgrammar Patch: 0.1.21 CWE-674
View details
HIGH CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can...

CVSS 8.8 EPSS 0.0% langflow CWE-269
View details
MEDIUM GHSA-vv6j-3g6g-2pvj

Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-vr7h-p6mm-wpmh

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-h3qp-7fh3-f8h4

Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers

picklescan Patch: 0.0.28
View details
MEDIUM GHSA-f745-w6jp-hpxx

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-f4x7-rfwp-v3xw

Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-86cj-95qr-2p4f

Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-4r9r-ch6f-vxmx

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

picklescan Patch: 0.0.28 CWE-345
View details
HIGH CVE-2025-48956

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request...

CVSS 7.5 EPSS 0.4% vllm CWE-400
View details
HIGH CVE-2025-9141

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

CVSS 8.8 vllm Patch: 0.10.1.1 CWE-502
View details
MEDIUM CVE-2025-57749

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive...

CVSS 6.5 n8n
View details
MEDIUM CVE-2025-52478

n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form...

CVSS 5.4 n8n
View details
HIGH CVE-2025-23298

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability...

CVSS 7.8
View details
HIGH GHSA-9gvj-pp9x-gcfr

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

picklescan Patch: 0.0.27 CWE-502
View details
UNKNOWN CVE-2025-55012

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent...

View details
HIGH CVE-2025-8747

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a...

CVSS 7.8 EPSS 0.0% keras CWE-502
View details
HIGH CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code...

CVSS 8.4 EPSS 0.3% CWE-502
View details
CRITICAL CVE-2025-54950

ExecuTorch out-of-bounds access vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-125
View details
CRITICAL CVE-2025-30405

ExecuTorch integer overflow vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-190
View details
CRITICAL CVE-2025-54951

ExecuTorch vulnerable to Heap-based Buffer Overflow

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-122
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial