AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 75 results — High severity, Active exploitation, has patchMarked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
CVE-2026-41680 A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file...
CVE-2026-6596 Keras: safe_mode bypass allows RCE via model deserialization
CVE-2026-1462 PraisonAI: unauthenticated SSRF via unvalidated webhook_url
CVE-2026-40114 praisonaiagents: SSRF in web_crawl exposes cloud metadata
CVE-2026-40160 PraisonAI: auto tools.py load enables local RCE
CVE-2026-40156 PraisonAI: AST sandbox bypass enables host RCE
CVE-2026-40158 praisonaiagents: env var expansion exposes production secrets
CVE-2026-40153 PraisonAI: auth bypass disables agent safety controls
CVE-2026-40149 PraisonAIAgents: SSRF exposes cloud metadata via web_crawl
CVE-2026-40150 praisonai: SSTI enables RCE via agent instructions
CVE-2026-39891 PraisonAI: recipe registry path traversal file write
CVE-2026-39308 PraisonAI: recipe path traversal allows arbitrary file write
CVE-2026-39306 PraisonAI: Zip Slip enables arbitrary file write / RCE
CVE-2026-39307 BentoML: malicious bento archive RCE via Jinja2 SSTI
CVE-2026-35044 BentoML: cmd injection RCE on cloud build infra
CVE-2026-35043 praisonaiagents: SSRF leaks cloud IAM credentials
CVE-2026-34954 PraisonAI: sandbox escape via shell=True blocklist bypass
CVE-2026-34955 PraisonAI: SSRF via api_base steals cloud IAM credentials
CVE-2026-34936 PraisonAI: OS command injection via run_python() shell escape
CVE-2026-34937 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert