AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

78

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 512 results — has patch
MEDIUM

PraisonAI: SQL injection via table_prefix exposes DB

GHSA-x783-xp3g-mqhp
--
Data Extraction Auth Bypass Agent Framework
PraisonAI Patch: 4.5.133 CWE-89 1 4 ATLAS
HIGH EXPLOIT AVAIL

PraisonAI: unauthenticated SSRF via unvalidated webhook_url

CVE-2026-40114
7.2
EPSS 0.0%
Auth Bypass Data Extraction Privacy Violation Agent API
PraisonAI Patch: 4.5.128 CWE-918 1 4 ATLAS
MEDIUM

PraisonAI: tool approval bypass leaks env credentials

GHSA-ffp3-3562-8cv3
5.5
Auth Bypass Data Extraction Prompt Injection Agent Framework
praisonaiagents Patch: 4.5.128 CWE-863 11 5 ATLAS
HIGH EXPLOIT AVAIL

praisonaiagents: SSRF in web_crawl exposes cloud metadata

CVE-2026-40160
--
EPSS 0.0%
Data Extraction Prompt Injection Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-918 11 6 ATLAS
HIGH

praisonaiagents: CORS bypass enables silent agent RCE

GHSA-x462-jjpc-q4q4
8.1
Auth Bypass Code Execution Data Extraction Agent Framework
praisonaiagents Patch: 4.5.128 CWE-942 11 5 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: MCP env inheritance exposes API keys

CVE-2026-40159
5.5
EPSS 0.0%
Supply Chain Data Leakage Data Extraction Agent Framework Plugin
PraisonAI Patch: 4.5.128 CWE-200 1 6 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: path traversal allows arbitrary file write via recipe unpack

CVE-2026-40157
--
EPSS 0.1%
Supply Chain Code Execution Agent Framework
PraisonAI Patch: 4.5.128 CWE-22 1 3 ATLAS
HIGH EXPLOIT AVAIL

PraisonAI: auto tools.py load enables local RCE

CVE-2026-40156
7.8
EPSS 0.0%
Supply Chain Code Execution Agent Framework Plugin
praisonai Patch: 4.5.128 CWE-94 1 4 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: decompression bomb causes disk exhaustion

CVE-2026-40148
6.5
EPSS 0.0%
DoS Supply Chain Agent Framework
PraisonAI Patch: 4.5.128 CWE-409 1 4 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: supply chain RCE via unverified template exec

CVE-2026-40154
9.3
EPSS 0.0%
Supply Chain Code Execution Agent Plugin Framework
PraisonAI Patch: 4.5.128 CWE-829 1 7 ATLAS
HIGH

PraisonAI: hardcoded approval bypass enables RCE

GHSA-qwgj-rrpj-75xm
8.8
Code Execution Auth Bypass Prompt Injection Agent Framework
PraisonAI Patch: 4.5.128 CWE-863 1 8 ATLAS
HIGH EXPLOIT AVAIL

PraisonAI: AST sandbox bypass enables host RCE

CVE-2026-40158
8.6
EPSS 0.0%
Code Execution Data Extraction Agent Framework
PraisonAI Patch: 4.5.128 CWE-94 1 5 ATLAS
MEDIUM EXPLOIT AVAIL

praisonaiagents: glob traversal leaks filesystem metadata

CVE-2026-40152
5.3
EPSS 0.0%
Data Extraction Privacy Violation Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-22 11 5 ATLAS
HIGH EXPLOIT AVAIL

praisonaiagents: env var expansion exposes production secrets

CVE-2026-40153
7.4
EPSS 0.0%
Data Extraction Prompt Injection Data Leakage Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-526 11 5 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: unauthenticated agent config and system prompt disclosure

CVE-2026-40151
5.3
EPSS 0.0%
Data Extraction Auth Bypass Agent API
PraisonAI Patch: 4.5.128 CWE-200 1 6 ATLAS
HIGH EXPLOIT AVAIL

PraisonAI: auth bypass disables agent safety controls

CVE-2026-40149
7.9
EPSS 0.0%
Auth Bypass Code Execution Agent Framework
PraisonAI Patch: 4.5.128 CWE-306 1 4 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: unbounded body read enables local DoS

CVE-2026-40115
6.2
EPSS 0.1%
DoS Auth Bypass Agent Framework
PraisonAI Patch: 4.5.128 CWE-770 1 3 ATLAS
CRITICAL EXPLOIT AVAIL

lollms: Stored XSS enables wormable account takeover

CVE-2026-1115
9.6
EPSS 0.0%
Code Execution Auth Bypass Data Extraction Framework API
lollms Patch: 2.2.0 CWE-79 5 ATLAS
MEDIUM EXPLOIT AVAIL

OpenClaw: SSRF via web-fetch enables internal network pivot

CVE-2026-6011
5.6
EPSS 0.1%
Data Extraction Privacy Violation Agent Plugin
openclaw Patch: 2026.1.29 CWE-918 4 4 ATLAS 1 incident
HIGH EXPLOIT AVAIL

PraisonAIAgents: SSRF exposes cloud metadata via web_crawl

CVE-2026-40150
7.7
EPSS 0.0%
Data Extraction Prompt Injection Privacy Violation Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-918 11 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial