AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 160 results — Critical severity, Active exploitationFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass...
CVE-2026-41276 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated...
CVE-2026-41268 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)...
CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the...
CVE-2026-41265 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41264 Flowise: RCE via MCP stdio command injection
CVE-2026-40933 OpenAI Codex CLI: RCE via malicious MCP config files
CVE-2025-61260 PraisonAI: path traversal allows arbitrary file write via recipe unpack
CVE-2026-40157 PraisonAI: supply chain RCE via unverified template exec
CVE-2026-40154 lollms: Stored XSS enables wormable account takeover
CVE-2026-1115 PraisonAI: RCE via shell injection in memory hooks executor
CVE-2026-40111 PraisonAI: YAML deserialization enables unauthenticated RCE
CVE-2026-39890 PraisonAI: path traversal exposes full filesystem via agent tools
CVE-2026-35615 PraisonAI: path traversal enables arbitrary file write/RCE
CVE-2026-39305 Claude Code: OS command injection, credential theft
CVE-2026-35022 Budibase: Unauthenticated RCE as root via webhook
CVE-2026-35216 MLflow: auth bypass in job API enables unauthenticated RCE
CVE-2026-0545 praisonaiagents: sandbox bypass enables full host RCE
CVE-2026-34938 MLflow: command injection via model_uri in mlserver mode
CVE-2026-0596 MLflow: RCE via unsanitized model dependency specs
CVE-2025-15379 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert