AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 15 of 15 results — KEV only, Active exploitation, no patchlangflow: Code Injection enables RCE
CVE-2026-33017 langflow: security flaw enables exploitation
CVE-2026-0770 n8n: Input Validation flaw enables exploitation
CVE-2026-21858 n8n: security flaw enables exploitation
CVE-2025-68613 langflow: security flaw enables exploitation
CVE-2025-34291 Langflow: Unauth RCE via code injection endpoint
CVE-2025-3248 LiteLLM: SSRF leaks OpenAI API key to attacker
CVE-2024-6587 Gradio: SSRF exposes internal network and cloud metadata
CVE-2024-4325 Ollama: path traversal enables RCE via model blob API
CVE-2024-37032 Gradio: path traversal enables arbitrary file read
CVE-2024-1561 Ray: unauthenticated RCE via job submission API
CVE-2023-48022 LangChain: SSRF in URL loader exposes internal network
CVE-2023-46229 LangChain: RCE bypass via __import__ in PAL chain
CVE-2023-44467 TorchServe: SSRF + RCE via unrestricted model URL loading
CVE-2023-43654 MLflow: path traversal allows arbitrary file read/write
CVE-2023-1177 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert