AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 524 results — High severity
HIGH CVE-2026-33497

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name}...

Data Extraction Auth Bypass Framework Agent
CVSS 7.5 langflow Patch: 1.7.1 CWE-22
View details
HIGH CVE-2026-33484

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without...

Auth Bypass Data Extraction Privacy Violation Framework API
CVSS 7.5 langflow CWE-284
View details
HIGH CVE-2026-33053

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with...

Supply Chain Code Execution DoS Framework Agent API
CVSS 8.8 EPSS 0.0% langflow CWE-639
View details
HIGH CVE-2026-33236

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

CVSS 8.1 EPSS 0.0% CWE-22
View details
HIGH CVE-2026-33155

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

EPSS 0.0% CWE-400
View details
HIGH CVE-2025-14287

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct...

Supply Chain Model Poisoning Code Execution Framework Model
CVSS 7.5 EPSS 0.1% mlflow Patch: 3.8.0rc0 CWE-94
View details
HIGH CVE-2026-27826

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

CVSS 8.2 EPSS 0.1% mcp-atlassian Patch: 0.17.0 CWE-918
View details
HIGH GHSA-5r2p-pjr8-7fh7

SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality

sagemaker Patch: 3.4.0 CWE-184
View details
HIGH CVE-2026-25048

xgrammar vulnerable to DoS via multi-layer nesting

EPSS 0.1% xgrammar Patch: 0.1.32 CWE-674
View details
HIGH CVE-2026-25750

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith...

Prompt Injection Data Leakage Code Execution Framework Agent API
CVSS 8.1 langsmith CWE-74
View details
HIGH GHSA-5hwf-rc88-82xm

Fickling missing RCE-capable modules in UNSAFE_IMPORTS

fickling Patch: 0.1.9 CWE-184
View details
HIGH GHSA-wccx-j62j-r448

Fickling has `always_check_safety()` bypass: pickle.loads and _pickle.loads remain unhooked

fickling Patch: 0.1.9 CWE-693
View details
HIGH CVE-2026-27905

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path...

Code Execution Framework Agent Model
CVSS 7.8 EPSS 0.0% bentoml CWE-59
View details
HIGH CVE-2026-28416

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP...

Data Extraction Code Execution Framework Model Training Data
CVSS 8.6 EPSS 0.0% gradio CWE-918
View details
HIGH CVE-2026-28414

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that...

Code Execution Data Extraction Framework API Model
CVSS 7.5 EPSS 0.0% gradio CWE-36
View details
HIGH CVE-2026-27498

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-94
View details
HIGH CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-89
View details
HIGH GHSA-mxhj-88fx-4pcv

Fickling: OBJ opcode call invisibility bypasses all safety checks

fickling Patch: 0.1.8 CWE-436
View details
HIGH CVE-2026-2033

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

Data Extraction Model Poisoning Code Execution Framework RAG Model
CVSS 8.1 EPSS 9.2% mlflow Patch: 3.8.0rc0 CWE-22
View details
HIGH CVE-2026-2472

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

EPSS 0.1% CWE-79
View details
HIGH CVE-2026-26286

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions...

Data Extraction Code Execution Social Engineering Framework RAG Agent
CVSS 8.5 CWE-918
View details
HIGH GHSA-97f8-7cmv-76j2

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

picklescan Patch: 1.0.3 CWE-184
View details
HIGH CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose...

Data Extraction Code Execution Framework RAG API
CVSS 7.5 EPSS 0.0% keras CWE-73
View details
HIGH CVE-2026-25580

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic...

CVSS 8.6 EPSS 0.0% pydantic-ai Patch: 1.56.0 CWE-918
View details
HIGH CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The...

Code Execution Social Engineering Agent RAG API
CVSS 7.2 n8n CWE-20
View details
HIGH CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or...

CVSS 8.8 n8n CWE-434
View details
HIGH CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating...

CVSS 8.1 n8n CWE-22
View details
HIGH CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to...

CVSS 7.7 n8n CWE-200
View details
HIGH CVE-2026-1777

SageMaker Python SDK has Exposed HMAC

CVSS 7.2 EPSS 0.0% sagemaker Patch: 3.2.0 CWE-201
View details
HIGH GHSA-9m3x-qqw2-h32h

picklescan missing detection by simple obfuscation of a `builtins.eval` call

picklescan Patch: 1.0.1 CWE-502
View details
HIGH CVE-2026-1117

Lollms has an Improper Access Control vulnerability

CVSS 8.2 EPSS 0.1% lollms Patch: 2.1.0 CWE-284
View details
HIGH CVE-2026-0599

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The...

CVSS 7.5 EPSS 0.2% CWE-400
View details
HIGH CVE-2025-10279

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with...

CVSS 7.0 EPSS 0.0% mlflow Patch: 3.4.0rc0 CWE-379
View details
HIGH CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT...

CVSS 8.8 EPSS 0.1% CWE-94
View details
HIGH CVE-2026-24779

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the...

CVSS 7.1 EPSS 0.0% vllm CWE-918
View details
HIGH CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file...

CVSS 8.8 EPSS 0.0% pytorch CWE-94
View details
HIGH CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

EPSS 11.4% langflow CWE-829
View details
HIGH CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a...

CVSS 7.4 CWE-79
View details
HIGH CVE-2026-21852

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before...

CVSS 7.5 claude_code CWE-522
View details
HIGH CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVSS 7.5 ollama
View details
HIGH CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

CVSS 7.5 ollama
View details
HIGH CVE-2025-33233

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution,...

CVSS 7.8 CWE-94
View details
HIGH CVE-2026-22219

Chainlit contain a server-side request forgery (SSRF) vulnerability

CVSS 7.7 EPSS 0.0% chainlit Patch: 2.9.4 CWE-918
View details
HIGH CVE-2026-0897

Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component

EPSS 0.0% keras Patch: 3.12.1 CWE-770
View details
HIGH CVE-2025-15514

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data...

CVSS 7.5 ollama CWE-395
View details
HIGH CVE-2024-58340

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method...

CVSS 7.5 langchain CWE-1333
View details
HIGH CVE-2024-58339

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query()...

CVSS 7.5 llamaindex CWE-770
View details
HIGH CVE-2024-14021

LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py....

CVSS 7.8 llamaindex CWE-502
View details
HIGH CVE-2026-22033

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

EPSS 0.0% label-studio CWE-79
View details
HIGH CVE-2025-14279

MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to...

CVSS 8.1 EPSS 0.0% mlflow Patch: 3.5.0 CWE-346
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial