AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 766 results — Active exploitation, no patchDagster: path traversal exposes arbitrary file read via gRPC
CVE-2025-51481 Transformers: ReDoS in DonutProcessor causes DoS
CVE-2025-3933 Contest Gallery WP Plugin: Stored XSS in OpenAI integration
CVE-2025-6716 OpenAI Operator: fullscreen spoofing captures credentials
CVE-2025-7021 Transformers: URL validation bypass exposes image pipeline
CVE-2025-3777 Transformers: ReDoS in dynamic module loader causes DoS
CVE-2025-3264 Transformers: ReDoS in config loader causes serving DoS
CVE-2025-3263 Transformers: ReDoS in chat.py causes CPU exhaustion
CVE-2025-3262 LiteLLM: SQL injection in key management API
CVE-2025-45809 n8n: DoS via empty filesystem URI in binary-data API
CVE-2025-49595 Slack MCP: zero-click exfiltration via link unfurling
CVE-2025-34072 Langchain-Chatchat: path traversal exposes system files
CVE-2025-6855 Langchain-Chatchat: path traversal in file API exposes host FS
CVE-2025-6854 Langchain-Chatchat: path traversal in KB upload
CVE-2025-6853 LLaMA-Factory: RCE via unsafe checkpoint deserialization
CVE-2025-53002 LangChain RequestsToolkit: SSRF exposes cloud metadata
CVE-2025-2828 jupyter_core: config hijack enables cross-user code exec
CVE-2025-30167 vLLM: input validation DoS crashes inference worker
CVE-2025-48944 vLLM: ReDoS crashes inference server via malformed regex
CVE-2025-48943 vLLM: DoS via malformed JSON schema guided param
CVE-2025-48942 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert