AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 377 results — Medium severity
MEDIUM CVE-2026-30886

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in...

Data Leakage Code Execution API Model Inference
CVSS 6.5 CWE-639
View details
MEDIUM CVE-2026-4538

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be...

Model Poisoning Code Execution Framework RAG Model
CVSS 5.3 CWE-20
View details
MEDIUM GHSA-5cxw-w2xg-2m8h

fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`

fickling Patch: 0.1.10 CWE-184
View details
MEDIUM GHSA-r48f-3986-4f9c

fickling modules linecache, difflib and gc are missing from the unsafe modules blocklist

fickling Patch: 0.1.10 CWE-184
View details
MEDIUM CVE-2026-2589

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup...

Data Extraction Data Leakage Supply Chain API RAG Plugin
CVSS 5.3 CWE-200
View details
MEDIUM CVE-2026-28277

LangGraph checkpoint loading has unsafe msgpack deserialization

CVSS 6.8 EPSS 0.0% langgraph Patch: 1.0.10 CWE-502
View details
MEDIUM CVE-2026-28415

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query...

Data Extraction Code Execution Auth Bypass Framework RAG API
CVSS 4.7 EPSS 0.0% gradio CWE-200
View details
MEDIUM CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically...

Supply Chain Model Poisoning Code Execution Framework Agent API
CVSS 5.9 EPSS 0.0% gradio CWE-522
View details
MEDIUM CVE-2026-27578

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts...

Prompt Injection Data Extraction Code Execution Agent RAG API
CVSS 5.4 n8n CWE-79
View details
MEDIUM CVE-2026-27794

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

CVSS 6.6 EPSS 0.3% CWE-502
View details
MEDIUM CVE-2026-27795

LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in...

Data Extraction Code Execution DoS Framework RAG Agent
CVSS 4.1 CWE-918
View details
MEDIUM GHSA-mhc9-48gj-9gp3

Fickling has safety check bypass via REDUCE+BUILD opcode sequence

fickling Patch: 0.1.8 CWE-184
View details
MEDIUM CVE-2026-27482

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

CVSS 5.9 EPSS 0.0% ray Patch: 2.54.0 CWE-306
View details
MEDIUM CVE-2025-12343

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple...

Code Execution Auth Bypass DoS Framework RAG Model
CVSS 5.5
View details
MEDIUM CVE-2026-26019

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting...

Data Extraction Framework RAG Agent
CVSS 4.1 langchain_community CWE-918
View details
MEDIUM CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send...

Code Execution Social Engineering Agent RAG API
CVSS 6.5 n8n CWE-20
View details
MEDIUM CVE-2026-25640

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an...

CVSS 5.4 EPSS 0.0% pydantic-ai Patch: 1.51.0 CWE-22
View details
MEDIUM CVE-2026-25054

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface,...

CVSS 5.4 n8n CWE-79
View details
MEDIUM CVE-2026-25051

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP...

CVSS 5.4 n8n CWE-79
View details
MEDIUM CVE-2026-1778

SageMaker Python SDK has Insecure TLS Configuration

CVSS 5.9 EPSS 0.0% sagemaker Patch: 3.1.1 CWE-295
View details
MEDIUM GHSA-m7j5-r2p5-c39r

picklescan vulnerable to arbitrary file create using logging.FileHandler

picklescan Patch: 1.0.1 CWE-502
View details
MEDIUM CVE-2025-6208

llama-index-core vulnerable to Uncontrolled Resource Consumption

CVSS 5.3 EPSS 0.0% llama-index-core Patch: 0.12.41 CWE-400
View details
MEDIUM GHSA-gpx9-96j6-pp87

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF)

CVSS 6.5 CWE-693
View details
MEDIUM CVE-2026-24123

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentofile.yaml` configuration allows path traversal...

CVSS 6.5 EPSS 0.0% bentoml CWE-22
View details
MEDIUM CVE-2025-68492

Chainlit contains an authorization bypass vulnerability

CVSS 4.2 EPSS 0.0% chainlit Patch: 2.8.5 CWE-639
View details
MEDIUM CVE-2025-68949

n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a...

CVSS 5.3 n8n CWE-134
View details
MEDIUM CVE-2025-14980

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated...

CVSS 6.5 CWE-200
View details
MEDIUM CVE-2026-21894

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to...

CVSS 6.5 n8n CWE-290
View details
MEDIUM CVE-2026-21851

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

CVSS 5.3 EPSS 0.0% monai Patch: 1.5.2 CWE-22
View details
MEDIUM CVE-2025-14371

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...

CVSS 4.3 CWE-862
View details
MEDIUM GHSA-6556-fwc2-fg2p

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

picklescan Patch: 0.0.33 CWE-94
View details
MEDIUM GHSA-cffc-mxrf-mhh4

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval

picklescan Patch: 0.0.33 CWE-94
View details
MEDIUM CVE-2025-68697

n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated...

CVSS 5.4 n8n CWE-269
View details
MEDIUM CVE-2025-61914

n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this...

CVSS 5.4 n8n CWE-79
View details
MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 EPSS 0.0% CWE-918
View details
MEDIUM CVE-2025-68477

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component that can issue arbitrary HTTP requests within a flow....

CVSS 6.5 EPSS 0.0% langflow CWE-918
View details
MEDIUM CVE-2025-63390

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote...

CVSS 5.3
View details
MEDIUM CVE-2025-13922

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview...

CVSS 6.5
View details
MEDIUM CVE-2025-13359

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and...

CVSS 6.5
View details
MEDIUM CVE-2025-13354

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin...

CVSS 4.3
View details
MEDIUM CVE-2025-62426

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request...

CVSS 6.5 EPSS 0.1% vllm CWE-770
View details
MEDIUM CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal...

CVSS 6.5 EPSS 0.1% vllm CWE-129
View details
MEDIUM CVE-2025-12732

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting()...

CVSS 4.3
View details
MEDIUM CVE-2025-11972

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due...

CVSS 4.9
View details
MEDIUM CVE-2025-12360

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up...

CVSS 4.3
View details
MEDIUM CVE-2025-12695

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

CVSS 5.9 EPSS 0.0% CWE-653
View details
MEDIUM CVE-2025-12058

The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF)....

EPSS 0.1% keras Patch: 3.12.0 CWE-502
View details
MEDIUM CVE-2025-11844

Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath...

CVSS 5.4 EPSS 0.0% smolagents CWE-643
View details
MEDIUM CVE-2025-60511

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in...

CVSS 4.3
View details
MEDIUM CVE-2025-61620

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

CVSS 6.5 vllm Patch: 0.11.0 CWE-20
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial