AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 435 results — High severity, Active exploitationMLflow: path traversal allows arbitrary directory deletion
CVE-2024-1560 MLflow: path traversal enables arbitrary file read
CVE-2024-1558 MLflow: path traversal exposes arbitrary server files
CVE-2024-1483 Gradio: path traversal leaks arbitrary files, potential RCE
CVE-2024-1728 Gradio: CI/CD command injection enables secrets exfil
CVE-2024-1540 LangChain: path traversal enables RCE and API key theft
CVE-2024-28088 Gradio: path traversal grants arbitrary file read
CVE-2023-51449 Transformers: unsafe deserialization enables RCE on load
CVE-2023-7018 HuggingFace Transformers: RCE via unsafe deserialization
CVE-2023-6730 MLflow: path traversal exposes arbitrary files (no auth)
CVE-2023-6909 MLflow: path traversal allows arbitrary file write
CVE-2023-6831 Gradio: command injection enables RCE on ML servers
CVE-2023-6572 MLflow: path traversal exposes arbitrary file read/write
CVE-2023-6753 MLflow: SSTI enables RCE in ML experiment tracking
CVE-2023-6709 MLflow: unauth REST API leaks sensitive ML data
CVE-2023-43472 MLflow: unauthenticated arbitrary file write via PUT
CVE-2023-6015 LangChain: prompt injection triggers SSRF via URL fetch
CVE-2023-32786 LangChain: SSRF in URL loader exposes internal network
CVE-2023-46229 MLflow: OS command injection enables local code execution
CVE-2023-4033 LangChain SQLDatabaseChain: SQL injection, DB exfil
CVE-2023-36189 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert