AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 160 results — Critical severity, Active exploitationstreamlit-geospatial: RCE via eval() on palette input
CVE-2024-41112 TorchServe: URL bypass enables arbitrary model loading
CVE-2024-35198 Gradio: code injection via component metadata (CVSS 9.8)
CVE-2024-39236 Langflow: unauthenticated RCE via custom component API
CVE-2024-37014 ChuanhuChatGPT: path traversal exposes LLM API keys
CVE-2024-3234 pytorch-lightning: RCE via deepdiff Delta deserialization
CVE-2024-5452 Gradio: CI/CD command injection enables secrets exfiltration
CVE-2024-4253 llama-cpp-python: SSTI in .gguf loader enables RCE
CVE-2024-34359 Keras: RCE via malicious model deserialization
CVE-2024-3660 MLflow: LFI via URI parsing allows arbitrary file read
CVE-2024-3573 BentoML: RCE via insecure deserialization (CVSS 10)
CVE-2024-2912 HuggingFace Transformers: RCE via pickle deserialization
CVE-2024-3568 gpt_academic: deserialization RCE, no auth required
CVE-2024-31224 LangChain TFIDFRetriever: SSRF/RCE via load_local
CVE-2024-2057 LangChain Experimental: RCE via Python sandbox escape
CVE-2024-27444 MLflow: XSS in recipe runner enables Jupyter RCE
CVE-2024-27133 MLflow: XSS in recipes enables client-side RCE
CVE-2024-27132 Gradio: unauthenticated LFI exposes full server filesystem
CVE-2024-0964 LlamaIndex: SQL injection in Text-to-SQL feature
CVE-2024-23751 Ray: unauthenticated RCE via job submission API
CVE-2023-48022 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert