AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsMistune Heading ID Attribute has Injection XSS
CVE-2026-44897 Mistune Math Plugin has an XSS Escape Bypass
CVE-2026-44708 LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-44843 Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-44566 Open WebUI has Improper Authorization Control
CVE-2026-44567 Open WebUI has stored XSS in Excel file preview
CVE-2026-44549 Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
CVE-2026-44568 Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
CVE-2026-44211 banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-44209 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs...
CVE-2026-42282 Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVE-2026-44560 Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVE-2026-44561 Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
CVE-2026-44564 Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVE-2026-44563 Open WebUI's Model Import Overwrites Any Model Without Ownership Check
CVE-2026-44562 Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
CVE-2026-44559 Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
CVE-2026-44557 Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVE-2026-44554 Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
CVE-2026-44558 Open WebUI's responses passthrough endpoint lacks access control authorization
CVE-2026-44556 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert