AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 167 results — has patch CVE-2026-33497 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name}...
CVE-2026-33309 Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to...
CVE-2025-15031 A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path...
CVE-2025-14287 A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct...
GHSA-5cxw-w2xg-2m8h fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`
GHSA-r48f-3986-4f9c fickling modules linecache, difflib and gc are missing from the unsafe modules blocklist
CVE-2026-27825 MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
CVE-2026-27826 MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
GHSA-5r2p-pjr8-7fh7 SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
CVE-2026-28277 LangGraph checkpoint loading has unsafe msgpack deserialization
CVE-2026-25048 xgrammar vulnerable to DoS via multi-layer nesting
GHSA-5hwf-rc88-82xm Fickling missing RCE-capable modules in UNSAFE_IMPORTS
GHSA-wccx-j62j-r448 Fickling has `always_check_safety()` bypass: pickle.loads and _pickle.loads remain unhooked
GHSA-g38g-8gr9-h9xp PickleScan has multiple stdlib modules with direct RCE not in blocklist
GHSA-vvpj-8cmc-gx39 PickleScan's pkgutil.resolve_name has a universal blocklist bypass
GHSA-7wx9-6375-f5wh PickleScan's profile.run blocklist mismatch allows exec() bypass
GHSA-mhc9-48gj-9gp3 Fickling has safety check bypass via REDUCE+BUILD opcode sequence
GHSA-mxhj-88fx-4pcv Fickling: OBJ opcode call invisibility bypasses all safety checks
CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not...
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
CVE-2026-27482 Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
GHSA-83pf-v6qq-pwmr Fickling has a detection bypass via stdlib network-protocol constructors
CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
GHSA-97f8-7cmv-76j2 Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
CVE-2026-25592 Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic...
CVE-2026-25580 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic...
CVE-2026-25640 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an...
CVE-2026-1777 SageMaker Python SDK has Exposed HMAC
CVE-2026-1778 SageMaker Python SDK has Insecure TLS Configuration
GHSA-m7j5-r2p5-c39r picklescan vulnerable to arbitrary file create using logging.FileHandler
GHSA-9m3x-qqw2-h32h picklescan missing detection by simple obfuscation of a `builtins.eval` call
CVE-2026-1117 Lollms has an Improper Access Control vulnerability
CVE-2025-6208 llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2025-10279 In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with...
CVE-2026-22219 Chainlit contain a server-side request forgery (SSRF) vulnerability
CVE-2026-0897 Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component
CVE-2025-68492 Chainlit contains an authorization bypass vulnerability
CVE-2025-14279 MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to...
CVE-2026-22612 Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22609 Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22608 Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22607 Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22606 Fickling has a bypass via runpy.run_path() and runpy.run_module()
GHSA-mcmc-2m55-j8jj vLLM introduced enhanced protection for CVE-2025-62164
GHSA-9726-w42j-3qjr picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-21851 MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
GHSA-46h3-79wf-xr6c Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
GHSA-955r-x9j8-7rhh Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
GHSA-6556-fwc2-fg2p Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
GHSA-rrxm-2pvv-m66x Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial