AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 910 results — Active exploitationpraisonaiagents: glob traversal leaks filesystem metadata
CVE-2026-40152 praisonaiagents: env var expansion exposes production secrets
CVE-2026-40153 PraisonAI: unauthenticated agent config and system prompt disclosure
CVE-2026-40151 PraisonAI: auth bypass disables agent safety controls
CVE-2026-40149 PraisonAI: unbounded body read enables local DoS
CVE-2026-40115 LiteLLM: RCE via bytecode rewriting in guardrails API
CVE-2026-40217 lollms: Stored XSS enables wormable account takeover
CVE-2026-1115 OpenClaw: SSRF via web-fetch enables internal network pivot
CVE-2026-6011 PraisonAIAgents: SSRF exposes cloud metadata via web_crawl
CVE-2026-40150 PraisonAI: arbitrary file read via unguarded skill tool
CVE-2026-40117 PraisonAI: unauth WebSocket drains OpenAI API credits
CVE-2026-40116 PraisonAI: arg injection injects env vars into Cloud Run
CVE-2026-40113 PraisonAI: XSS via no-op HTML sanitizer in agent output
CVE-2026-40112 PraisonAI: RCE via shell injection in memory hooks executor
CVE-2026-40111 openai-realtime-ui: SSRF in API proxy endpoint
CVE-2026-5803 praisonai: SSTI enables RCE via agent instructions
CVE-2026-39891 PraisonAI: YAML deserialization enables unauthenticated RCE
CVE-2026-39890 LobeChat: auth bypass via forged XOR obfuscated header
CVE-2026-39411 lollms: sessions persist after password reset
CVE-2026-1163 text-generation-webui: unauthenticated path traversal file read
CVE-2026-35485 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert