AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
CRITICAL CVE-2025-54950

ExecuTorch out-of-bounds access vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-125
View details
MEDIUM CVE-2025-54952

ExecuTorch integer overflow vulnerability leads to code execution

EPSS 0.2% executorch CWE-680
View details
CRITICAL CVE-2025-54951

ExecuTorch vulnerable to Heap-based Buffer Overflow

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-122
View details
CRITICAL CVE-2025-53767

Azure OpenAI Elevation of Privilege Vulnerability

CVSS 10.0 azure_openai
View details
MEDIUM CVE-2025-44779

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

CVSS 6.6 ollama
View details
MEDIUM CVE-2025-5197

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function,...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
CRITICAL CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.

CVSS 9.8 langchain-chatglm-webui
View details
HIGH CVE-2025-7725

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 7.2
View details
MEDIUM GHSA-r54c-2xmf-2cf3

MS SWIFT Deserialization RCE Vulnerability

CWE-502
View details
CRITICAL CVE-2025-54381

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF...

CVSS 9.9 EPSS 0.5% bentoml CWE-918
View details
CRITICAL CVE-2025-46059

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise...

CVSS 9.8
View details
CRITICAL CVE-2025-5120

A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The...

CVSS 10.0 EPSS 0.3% smolagents CWE-94
View details
HIGH CVE-2025-54413

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which can be exploited to access...

EPSS 0.0% CWE-351
View details
HIGH CVE-2025-54412

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide...

EPSS 0.0% CWE-351
View details
MEDIUM CVE-2025-54558

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

CVSS 4.1
View details
MEDIUM CVE-2025-7780

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before...

CVSS 6.5
View details
MEDIUM CVE-2025-51471

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a...

CVSS 6.9 ollama
View details
MEDIUM CVE-2025-51481

Dagster Local File Inclusion vulnerability

CVSS 6.6 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-53621

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace...

CVSS 6.9
View details
HIGH CVE-2025-30402

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

CVSS 8.1 EPSS 0.1% executorch Patch: 0.7.0-rc1 CWE-122
View details
MEDIUM CVE-2025-3933

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-6716

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 6.4
View details
MEDIUM CVE-2025-7021

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login...

CVSS 6.5 operator
View details
MEDIUM CVE-2025-6211

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

CVSS 6.5 EPSS 0.1% llama-index Patch: 0.12.41 CWE-440
View details
HIGH CVE-2025-6209

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS 7.5 EPSS 0.1% llama-index-core Patch: 0.12.41 CWE-29
View details
HIGH CVE-2025-6386

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

CVSS 7.5 EPSS 0.1% lollms CWE-203
View details
MEDIUM CVE-2025-6210

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

CVSS 6.2 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-5472

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

CVSS 6.5 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
HIGH CVE-2025-3225

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVSS 7.5 EPSS 0.1% CWE-776
View details
MEDIUM CVE-2025-3044

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

CVSS 5.3 EPSS 0.1% CWE-440
View details
HIGH CVE-2025-3046

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

CVSS 7.5 EPSS 0.1% CWE-22
View details
LOW CVE-2025-3777

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using...

CVSS 3.5 EPSS 0.0% transformers CWE-20
View details
MEDIUM CVE-2025-3264

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-3263

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
HIGH CVE-2025-3262

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-3108

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

CVSS 5.0 EPSS 1.1% llama-index-core Patch: 0.12.41 CWE-1112
View details
MEDIUM CVE-2025-52554

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow...

CVSS 4.3 n8n
View details
MEDIUM CVE-2025-45809

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

CVSS 5.4 litellm
View details
MEDIUM CVE-2025-49595

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or...

CVSS 4.9 n8n
View details
UNKNOWN CVE-2025-34072

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes...

View details
HIGH CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation...

CVSS 8.8 EPSS 0.2% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-6854

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The...

CVSS 4.3 EPSS 0.1% langchain-chatchat CWE-22
View details
CRITICAL CVE-2025-6853

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the...

CVSS 9.8 EPSS 0.2% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains...

CVSS 5.4 n8n
View details
CRITICAL CVE-2025-53002

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training...

CVSS 9.8 EPSS 1.6% llamafactory CWE-94
View details
CRITICAL CVE-2025-2828

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically,...

CVSS 10.0 EPSS 0.1% langchain CWE-918
View details
MEDIUM CVE-2025-52967

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

CVSS 5.8 EPSS 0.1% mlflow Patch: 3.1.0 CWE-918
View details
HIGH CVE-2025-5018

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and...

CVSS 7.1
View details
CRITICAL CVE-2025-1793

llama_index vulnerable to SQL Injection

CVSS 9.8 EPSS 0.0% llama-index Patch: 0.12.28 CWE-89
View details
HIGH CVE-2025-30167

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS 7.3 EPSS 0.0% CWE-427
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial