AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 160 results — Critical severity, Active exploitation
CRITICAL EXPLOIT AVAIL

n8n: Protection Bypass circumvents security controls

CVE-2025-68668
9.9
EPSS 0.1%
Code Execution Auth Bypass Agent Framework Plugin
n8n 16 6 ATLAS
CRITICAL EXPLOIT AVAIL

langchain.js: Deserialization enables RCE

CVE-2025-68665
9.1
EPSS 0.1%
Supply Chain Code Execution Data Extraction Framework Agent
langchain.js 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

cai-framework: Command Injection enables RCE

CVE-2025-67511
9.6
EPSS 0.1%
Code Execution Prompt Injection Agent Framework
CWE-77 7 ATLAS
CRITICAL KEV

ray: Code Injection enables RCE

CVE-2025-62593
--
EPSS 0.0%
Code Execution Auth Bypass Social Engineering Framework
ray Patch: 2.52.0 CWE-94 845 8 ATLAS
CRITICAL EXPLOIT AVAIL

mlx: security flaw enables exploitation

CVE-2025-62608
9.1
EPSS 0.1%
Supply Chain Code Execution Data Extraction Framework Training Data
mlx CWE-122 283 6 ATLAS
CRITICAL EXPLOIT AVAIL

keras: Path Traversal enables file access

CVE-2025-12060
9.8
EPSS 0.1%
Supply Chain Code Execution Framework Training Data
keras Patch: 3.12.0 CWE-22 1.5K 4 ATLAS
CRITICAL EXPLOIT AVAIL

mlflow: Path Traversal enables file access

CVE-2025-11201
9.8
EPSS 9.8%
Code Execution Auth Bypass Framework
mlflow CWE-22 624 6 ATLAS
CRITICAL EXPLOIT AVAIL

keras: Deserialization enables RCE

CVE-2025-49655
9.8
EPSS 0.1%
Code Execution Supply Chain Framework Model
keras Patch: 3.11.3 CWE-502 1.5K 5 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: path traversal in file tools leads to RCE

CVE-2025-61913
9.9
EPSS 0.8%
Code Execution Data Extraction Auth Bypass Agent Plugin Framework
flowise 6 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: Unauthenticated RCE via MCP config injection

CVE-2025-59528
10.0
EPSS 83.9%
Code Execution Supply Chain Agent Framework Plugin
flowise 5 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise Cloud: cross-tenant env var exposure leaks API keys

CVE-2025-59434
9.6
EPSS 0.1%
Data Extraction Auth Bypass Privacy Violation Framework API Agent
6 ATLAS
CRITICAL EXPLOIT AVAIL SCANNER

Flowise: auth bypass in reset flow allows full ATO

CVE-2025-58434
9.8
EPSS 21.0%
Auth Bypass Data Extraction Agent Framework
flowise 5 ATLAS
CRITICAL EXPLOIT AVAIL

langchaingo: Jinja2 SSTI allows host filesystem read

CVE-2025-9556
9.8
EPSS 0.1%
Code Execution Data Extraction Framework Agent
5 ATLAS
CRITICAL EXPLOIT AVAIL

n8n-workflows: path traversal in download_workflow endpoint

CVE-2025-55526
9.1
EPSS 0.6%
Data Extraction Auth Bypass Code Execution Agent Framework API
fastapi 16 5 ATLAS
CRITICAL EXPLOIT AVAIL

ExecuTorch: OOB read in model loader enables RCE

CVE-2025-54950
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-125 2 4 ATLAS
CRITICAL EXPLOIT AVAIL

Azure OpenAI: SSRF EoP, no auth required (CVSS 10)

CVE-2025-53767
10.0
EPSS 0.5%
Auth Bypass Data Extraction Privacy Violation API Inference
azure_openai 13.6K 6 ATLAS
CRITICAL EXPLOIT AVAIL

ChatGLM-Webui: arbitrary file read, no auth required

CVE-2025-45150
9.8
EPSS 0.1%
Data Extraction Auth Bypass Framework API
langchain-chatglm-webui 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: unauthenticated SSRF via file upload URLs

CVE-2025-54381
9.9
EPSS 0.7%
Supply Chain Data Extraction Auth Bypass Framework Inference API
bentoml CWE-918 22 5 ATLAS
CRITICAL EXPLOIT AVAIL

LangChain GmailToolkit: indirect prompt injection to RCE

CVE-2025-46059
9.8
EPSS 0.3%
Prompt Injection Code Execution Data Extraction Framework Agent Plugin
6 ATLAS
CRITICAL EXPLOIT AVAIL

smolagents: sandbox escape enables unauthenticated RCE

CVE-2025-5120
10.0
EPSS 0.4%
Code Execution Supply Chain Data Leakage Framework Agent
smolagents CWE-94 86 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial