AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

226

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
CRITICAL

Flowise: prompt injection bypasses Python sandbox RCE

GHSA-v38x-c887-992f
--
Prompt Injection Code Execution Agent Framework
flowise-components Patch: 3.1.0 CWE-184 8 ATLAS
MEDIUM

OpenClaw: path traversal in memory_get reads arbitrary workspace files

GHSA-f934-5rqf-xx47
--
Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.4.15 CWE-22 4 4 ATLAS 1 incident
HIGH

openclaw: path traversal leaks files and NTLM credentials

GHSA-mr34-9552-qr95
--
Data Extraction Data Leakage Agent Plugin
openclaw Patch: 2026.4.15 CWE-22 4 4 ATLAS 1 incident
CRITICAL

OpenClaw: auth bypass enables unauthenticated command exec

GHSA-xh72-v6v9-mwhc
--
Auth Bypass Code Execution Agent Plugin
openclaw Patch: 2026.4.15 CWE-287 4 4 ATLAS 1 incident
HIGH

OpenClaw: auth bypass lets DM senders run room commands

GHSA-2gvc-4f3c-2855
--
Auth Bypass Code Execution Agent
openclaw Patch: 2026.4.15 CWE-863 4 3 ATLAS 1 incident
HIGH

OpenClaw: stale bearer token survives SecretRef rotation

GHSA-xmxx-7p24-h892
--
Auth Bypass Agent API
openclaw Patch: 2026.4.15 CWE-324 4 3 ATLAS 1 incident
HIGH

PraisonAI: SQL injection across 9 DB backends

GHSA-rg3h-x3jw-7jm5
8.1
Data Extraction Code Execution Data Leakage Framework Agent
praisonaiagents Patch: 1.6.8 CWE-89 11 4 ATLAS
CRITICAL

PraisonAI: RCE via MCP command injection

GHSA-9qhq-v63v-fv3j
9.8
Code Execution Supply Chain Agent Framework
praisonai Patch: 4.5.149 CWE-78 1 6 ATLAS
MEDIUM

Claude Code: config hijack via unprotected ProgramData dir

CVE-2026-35603
--
EPSS 0.0%
Supply Chain Auth Bypass Agent
@anthropic-ai/claude-code Patch: 2.1.75 CWE-426 4 ATLAS
MEDIUM

openclaw: CDP SSRF enables internal host pivot

GHSA-f7fh-qg34-x2xh
--
Auth Bypass Data Extraction Agent Framework
openclaw Patch: 2026.4.5 CWE-918 4 2 ATLAS 1 incident
MEDIUM

OpenClaw: auth bypass leaks host files via media path

GHSA-jhpv-5j76-m56h
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.10 CWE-863 4 4 ATLAS 1 incident
HIGH

openclaw: path traversal exposes host files via media tags

GHSA-66r7-m7xm-v49h
--
Data Extraction Data Leakage Privacy Violation Agent
openclaw Patch: 2026.4.10 CWE-22 4 4 ATLAS 1 incident
HIGH

openclaw: exec approval bypass via opaque multi-call binaries

GHSA-2cq5-mf3v-mx44
--
Auth Bypass Code Execution Supply Chain Agent Plugin
openclaw Patch: 2026.4.12 CWE-863 4 5 ATLAS 1 incident
HIGH

openclaw: auth bypass lets write-scope callers mutate admin config

GHSA-7jp6-r74r-995q
--
Auth Bypass Data Leakage Agent Framework
openclaw Patch: 2026.4.10 CWE-266 4 3 ATLAS 1 incident
HIGH

openclaw: sandbox escape via host=node exec routing bypass

GHSA-736r-jwj6-4w23
--
Auth Bypass Code Execution Agent Framework
openclaw Patch: 2026.4.10 CWE-863 4 5 ATLAS 1 incident
MEDIUM

openclaw: SSRF bypass via browser navigation guard gap

GHSA-536q-mj95-h29h
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.10 CWE-918 4 5 ATLAS 1 incident
MEDIUM

openclaw: CDP pivot bypasses file:// navigation guards

GHSA-qmwg-qprg-3j38
--
Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.4.9 CWE-693 4 4 ATLAS 1 incident
HIGH

openclaw: untrusted plugin auto-enabled during onboarding

GHSA-939r-rj45-g2rj
--
Supply Chain Auth Bypass Agent Plugin
openclaw Patch: 2026.4.9 CWE-829 4 4 ATLAS 1 incident
MEDIUM

openclaw: SSRF bypass in existing browser session routes

GHSA-527m-976r-jf79
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.10 CWE-918 4 4 ATLAS 1 incident
MEDIUM

openclaw: SSRF policy bypass in browser tab actions

GHSA-rj2p-j66c-mgqh
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.10 CWE-918 4 4 ATLAS 1 incident

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial