AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 973 results — no patch
CRITICAL CVE-2025-33244

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions...

Code Execution Supply Chain Data Extraction Framework Training Data
CVSS 9.0 CWE-502
View details
UNKNOWN CVE-2026-33401

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test...

Data Extraction Auth Bypass Privacy Violation Inference API
CWE-918
View details
HIGH CVE-2026-33484

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without...

Auth Bypass Data Extraction Privacy Violation Framework API
CVSS 7.5 langflow CWE-284
View details
CRITICAL CVE-2026-33475

Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow...

Supply Chain Code Execution Data Extraction Framework Agent
CVSS 9.1 langflow CWE-74
View details
MEDIUM CVE-2026-30886

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in...

Data Leakage Code Execution API Model Inference
CVSS 6.5 CWE-639
View details
MEDIUM CVE-2026-4538

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be...

Model Poisoning Code Execution Framework RAG Model
CVSS 5.3 CWE-20
View details
HIGH CVE-2026-33053

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with...

Supply Chain Code Execution DoS Framework Agent API
CVSS 8.8 EPSS 0.0% langflow CWE-639
View details
CRITICAL CVE-2026-33017

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows...

Model Poisoning Code Execution Framework Agent API
CVSS 9.8 EPSS 0.5% langflow CWE-95
View details
HIGH CVE-2026-33236

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

CVSS 8.1 EPSS 0.0% CWE-22
View details
HIGH CVE-2026-33155

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

EPSS 0.0% CWE-400
View details
CRITICAL CVE-2026-28500

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to...

Supply Chain Model Poisoning Code Execution Framework RAG API
CVSS 9.1 EPSS 0.0% onnx CWE-345
View details
UNKNOWN CVE-2026-25083

GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper...

Prompt Injection Data Leakage Model Poisoning API RAG Inference
CWE-862
View details
CRITICAL CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to...

Data Extraction Data Leakage Code Execution Inference RAG Agent
CVSS 9.8 EPSS 0.0% vllm CWE-918
View details
CRITICAL CVE-2026-30821

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS,...

Code Execution Framework RAG Plugin
CVSS 9.8 CWE-434
View details
MEDIUM CVE-2026-2589

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup...

Data Extraction Data Leakage Supply Chain API RAG Plugin
CVSS 5.3 CWE-200
View details
HIGH CVE-2026-25750

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith...

Prompt Injection Data Leakage Code Execution Framework Agent API
CVSS 8.1 langsmith CWE-74
View details
HIGH CVE-2026-27905

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path...

Code Execution Framework Agent Model
CVSS 7.8 EPSS 0.0% bentoml CWE-59
View details
HIGH CVE-2026-28416

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP...

Data Extraction Code Execution Framework Model Training Data
CVSS 8.6 EPSS 0.0% gradio CWE-918
View details
MEDIUM CVE-2026-28415

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query...

Data Extraction Code Execution Auth Bypass Framework RAG API
CVSS 4.7 EPSS 0.0% gradio CWE-200
View details
HIGH CVE-2026-28414

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that...

Code Execution Data Extraction Framework API Model
CVSS 7.5 EPSS 0.0% gradio CWE-36
View details
MEDIUM CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically...

Supply Chain Model Poisoning Code Execution Framework Agent API
CVSS 5.9 EPSS 0.0% gradio CWE-522
View details
CRITICAL CVE-2026-27966

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically...

Prompt Injection Code Execution Framework RAG Agent
CVSS 9.8 EPSS 0.2% langflow CWE-94
View details
MEDIUM CVE-2026-27578

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts...

Prompt Injection Data Extraction Code Execution Agent RAG API
CVSS 5.4 n8n CWE-79
View details
CRITICAL CVE-2026-27577

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following...

Model Poisoning Code Execution Social Engineering Agent RAG API
CVSS 9.9 n8n CWE-94
View details
HIGH CVE-2026-27498

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-94
View details
HIGH CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-89
View details
CRITICAL CVE-2026-27495

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in...

Code Execution Social Engineering Agent RAG API
CVSS 9.9 n8n CWE-94
View details
CRITICAL CVE-2026-27494

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node...

Code Execution Agent RAG API
CVSS 9.9 n8n CWE-497
View details
CRITICAL CVE-2026-27493

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an...

Code Execution Agent RAG API
CVSS 9.0 n8n CWE-94
View details
MEDIUM CVE-2026-27794

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

CVSS 6.6 EPSS 0.3% CWE-502
View details
MEDIUM CVE-2026-27795

LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in...

Data Extraction Code Execution DoS Framework RAG Agent
CVSS 4.1 CWE-918
View details
UNKNOWN CVE-2026-2492

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of...

Code Execution Auth Bypass Framework RAG Plugin
CWE-427
View details
HIGH CVE-2026-2472

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

EPSS 0.1% CWE-79
View details
HIGH CVE-2026-26286

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions...

Data Extraction Code Execution Social Engineering Framework RAG Agent
CVSS 8.5 CWE-918
View details
MEDIUM CVE-2025-12343

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple...

Code Execution Auth Bypass DoS Framework RAG Model
CVSS 5.5
View details
CRITICAL CVE-2026-2654

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to...

CVSS 9.8 smolagents
View details
HIGH CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose...

Data Extraction Code Execution Framework RAG API
CVSS 7.5 EPSS 0.0% keras CWE-73
View details
MEDIUM CVE-2026-26019

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting...

Data Extraction Framework RAG Agent
CVSS 4.1 langchain_community CWE-918
View details
LOW CVE-2026-26013

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation...

Data Extraction Framework RAG Agent
CVSS 3.7 EPSS 0.0% langchain_core CWE-918
View details
MEDIUM CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send...

Code Execution Social Engineering Agent RAG API
CVSS 6.5 n8n CWE-20
View details
HIGH CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The...

Code Execution Social Engineering Agent RAG API
CVSS 7.2 n8n CWE-20
View details
CRITICAL CVE-2026-25115

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and...

CVSS 9.9 n8n CWE-693
View details
HIGH CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or...

CVSS 8.8 n8n CWE-434
View details
HIGH CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating...

CVSS 8.1 n8n CWE-22
View details
MEDIUM CVE-2026-25054

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface,...

CVSS 5.4 n8n CWE-79
View details
CRITICAL CVE-2026-25053

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to...

CVSS 9.9 n8n CWE-78
View details
CRITICAL CVE-2026-25052

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify...

CVSS 9.9 n8n CWE-367
View details
MEDIUM CVE-2026-25051

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP...

CVSS 5.4 n8n CWE-79
View details
CRITICAL CVE-2026-25049

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in...

CVSS 9.9 n8n CWE-913
View details
HIGH CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to...

CVSS 7.7 n8n CWE-200
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial