AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

226

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
MEDIUM

openclaw: insufficient authz allows agent config persistence

GHSA-f3h5-h452-vp3j
--
Auth Bypass Supply Chain Agent Plugin
openclaw Patch: 2026.4.10 CWE-266 4 3 ATLAS 1 incident
HIGH

openclaw: CDP relay exposes browser DevTools on 0.0.0.0

GHSA-525j-hqq2-66r4
--
Auth Bypass Data Extraction Agent
openclaw Patch: 2026.4.10 CWE-284 4 4 ATLAS 1 incident
HIGH

openclaw: trust bypass loads untrusted workspace plugins

GHSA-82qx-6vj7-p8m2
--
Supply Chain Auth Bypass Code Execution Agent Plugin Framework
openclaw Patch: 2026.4.10 CWE-862 4 4 ATLAS 1 incident
MEDIUM

openclaw: path traversal bypasses workspace filesystem guard

GHSA-jf25-7968-h2h5
--
Auth Bypass Code Execution Agent Plugin
openclaw Patch: 2026.4.10 CWE-22 4 5 ATLAS 1 incident
MEDIUM

openclaw: Browser SSRF exposes internal services by default

GHSA-53vx-pmqw-863c
--
Auth Bypass Data Extraction Supply Chain Agent Plugin Framework
openclaw Patch: 2026.4.14 CWE-918 4 5 ATLAS 1 incident
MEDIUM

openclaw: DNS rebinding bypasses browser SSRF protection

GHSA-xq94-r468-qwgj
--
Auth Bypass Data Extraction Agent Framework
openclaw Patch: 2026.4.10 CWE-350 4 3 ATLAS 1 incident
MEDIUM

openclaw: QQBot SSRF leaks internal service responses

GHSA-2767-2q9v-9326
--
Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.4.12 CWE-918 4 4 ATLAS 1 incident
MEDIUM

openclaw: .env injection hijacks agent runtime config

GHSA-7wv4-cc7p-jhxc
--
Supply Chain Code Execution Auth Bypass Agent Plugin Framework
openclaw Patch: 2026.4.9 CWE-15 4 5 ATLAS 1 incident
MEDIUM

openclaw: path traversal bypasses media sandbox

GHSA-c9h3-5p7r-mrjh
--
Auth Bypass Data Leakage Data Extraction Agent Framework Plugin
openclaw Patch: 2026.4.10 CWE-22 4 4 ATLAS 1 incident
MEDIUM

openclaw: auth bypass via empty approver list

GHSA-49cg-279w-m73x
--
Auth Bypass Agent Framework
openclaw Patch: 2026.4.12 CWE-862 4 3 ATLAS 1 incident
MEDIUM

openclaw: trust escalation via unsanitized agent hook events

GHSA-7g8c-cfr3-vqqr
--
Auth Bypass Prompt Injection Agent Framework Plugin
openclaw Patch: 2026.4.10 CWE-269 4 4 ATLAS 1 incident
HIGH

openclaw: env denylist bypass enables code exec in agents

GHSA-vfp4-8x56-j7c5
--
Code Execution Auth Bypass Agent Plugin
openclaw Patch: 2026.4.10 CWE-184 4 4 ATLAS 1 incident
MEDIUM

openclaw: OS command injection via shell env-argv bypass

GHSA-j6c7-3h5x-99g9
--
Code Execution Supply Chain Auth Bypass Agent Framework Plugin
openclaw Patch: 2026.4.12 CWE-78 4 5 ATLAS 1 incident
MEDIUM

openclaw: auth bypass enables persistent memory config change

GHSA-5gjc-grvm-m88j
--
Auth Bypass Privacy Violation Agent Framework
openclaw Patch: 2026.4.10 CWE-266 4 3 ATLAS 1 incident
LOW

openclaw: auth bypass in Teams SSO invoke handler

GHSA-gc9r-867r-j85f
--
Auth Bypass Agent API
openclaw Patch: 2026.4.14 CWE-862 4 4 ATLAS 1 incident
LOW

openclaw: group policy bypass in delivery queue recovery

GHSA-r77c-2cmr-7p47
--
Auth Bypass Agent
openclaw Patch: 2026.4.14 CWE-862 4 3 ATLAS 1 incident
MEDIUM

openclaw: privilege retention via async exec completion miss

GHSA-g375-h3v6-4873
--
Auth Bypass Code Execution Agent
openclaw Patch: 2026.4.10 CWE-269 4 4 ATLAS 1 incident
HIGH

openclaw: WebSocket DoS via oversized frame ingestion

GHSA-vw3h-q6xq-jjm5
--
DoS Agent
openclaw Patch: 2026.4.10 CWE-400 4 4 ATLAS 1 incident
MEDIUM

openclaw: auth bypass preserves owner-level agent execution

GHSA-g2hm-779g-vm32
--
Auth Bypass Code Execution Agent Plugin
openclaw Patch: 2026.4.14 CWE-863 4 4 ATLAS 1 incident
MEDIUM

openclaw: SSRF bypass exposes internal pages in browser tool

GHSA-c4qm-58hj-j6pj
--
Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.4.14 CWE-918 4 4 ATLAS 1 incident

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial