AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 131 results — Critical severity, Active exploitation, no patchFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass...
CVE-2026-41276 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated...
CVE-2026-41268 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)...
CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the...
CVE-2026-41265 OpenAI Codex CLI: RCE via malicious MCP config files
CVE-2025-61260 Claude Code: OS command injection, credential theft
CVE-2026-35022 Budibase: Unauthenticated RCE as root via webhook
CVE-2026-35216 MLflow: auth bypass in job API enables unauthenticated RCE
CVE-2026-0545 MLflow: command injection via model_uri in mlserver mode
CVE-2026-0596 langflow: security flaw enables exploitation
CVE-2026-33475 langflow: Code Injection enables RCE
CVE-2026-33017 onnx: Integrity Verification bypass enables tampering
CVE-2026-28500 OpenClaw: RCE via request-side prompt injection
CVE-2026-30741 vllm: SSRF allows internal network access
CVE-2026-25960 Flowise: auth bypass exposes NVIDIA NIM container endpoints
CVE-2026-30824 flowise: Arbitrary File Upload enables RCE
CVE-2026-30821 langflow: Code Injection enables RCE
CVE-2026-27966 smolagents: SSRF allows internal network access
CVE-2026-2654 langroid: Code Injection enables RCE
CVE-2026-25481 cai-framework: Command Injection enables RCE
CVE-2026-25130 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert