AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Weekly CISO Take + top threats
Get the week's most critical AI security threats delivered every Monday. Free, no spam.
Latest AI Security Threats
Showing 50 of 66 results — Medium severity, has patch GHSA-5cxw-w2xg-2m8h fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`
GHSA-r48f-3986-4f9c fickling modules linecache, difflib and gc are missing from the unsafe modules blocklist
CVE-2026-28277 LangGraph checkpoint loading has unsafe msgpack deserialization
GHSA-mhc9-48gj-9gp3 Fickling has safety check bypass via REDUCE+BUILD opcode sequence
CVE-2026-27482 Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
CVE-2026-25640 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an...
CVE-2026-1778 SageMaker Python SDK has Insecure TLS Configuration
GHSA-m7j5-r2p5-c39r picklescan vulnerable to arbitrary file create using logging.FileHandler
CVE-2025-6208 llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2025-68492 Chainlit contains an authorization bypass vulnerability
CVE-2026-21851 MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
GHSA-6556-fwc2-fg2p Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
GHSA-cffc-mxrf-mhh4 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
CVE-2025-12058 The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF)....
CVE-2025-61620 vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-8917 clearml is vulnerable to Path Traversal through its `safe_extract` function
CVE-2025-58446 xgrammar vulnerable to denial of service by huge enum grammar
GHSA-q77w-mwjj-7mqx Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start
GHSA-49gj-c84q-6qm9 Picklescan is missing detection when calling built-in python cProfile.run
GHSA-9w88-8rmg-7g2p Picklescan is missing detection when calling built-in python cProfile.runctx
GHSA-fqq6-7vqf-w3fg Picklescan is missing detection when calling built-in python doctest.debug_script
GHSA-3gf5-cxq9-w223 Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
GHSA-j343-8v2j-ff7w Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-m869-42cg-3xwr Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode
GHSA-p9w7-82w4-7q8m Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label
GHSA-xp4f-hrf8-rxw7 Picklescan is missing detection when calling built-in python ensurepip._run_pip
GHSA-4whj-rm5r-c2v8 Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof
GHSA-9xph-j2h6-g47v Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity
GHSA-8r4j-24qv-fmq9 Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
GHSA-cj3c-v495-4xqh Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter
GHSA-7cq8-mj8x-j263 Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
GHSA-6w4w-5w54-rjvr Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
GHSA-3vg9-h568-4w9m Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
GHSA-f54q-57x4-jg88 Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads
GHSA-6vqj-c2q5-j97w Picklescan has a missing detection when calling built-in python profile.Profile.runctx
GHSA-x696-vm39-cp64 Picklescan has a missing detection when calling built-in python profile.Profile.run
GHSA-g344-hcph-8vgg Picklescan has a missing detection when calling built-in python trace.Trace.runctx
GHSA-5qwp-399c-mjwf Picklescan has a missing detection when calling built-in python trace.Trace.run
GHSA-vv6j-3g6g-2pvj Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
GHSA-vr7h-p6mm-wpmh Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-h3qp-7fh3-f8h4 Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers
GHSA-f745-w6jp-hpxx Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
GHSA-f4x7-rfwp-v3xw Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
GHSA-86cj-95qr-2p4f Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
GHSA-4r9r-ch6f-vxmx Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
CVE-2025-6211 LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-5472 LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-3108 LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-52967 gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
GHSA-j828-28rj-hfhp vLLM vulnerable to Regular Expression Denial of Service
Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial