AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

78

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 570 results — Medium severity
MEDIUM

langchain_community: SSRF allows internal network access

CVE-2026-26019
4.1
EPSS 0.0%
Data Extraction Framework RAG Agent
langchain_community CWE-918 2.6K 8 ATLAS
MEDIUM

n8n: Input Validation flaw enables exploitation

CVE-2026-25631
6.5
EPSS 0.0%
Code Execution Social Engineering Agent RAG API
n8n CWE-20 16 7 ATLAS
MEDIUM

pydantic-ai: Path Traversal enables file access

CVE-2026-25640
5.4
EPSS 0.0%
Code Execution Data Extraction Framework Agent
pydantic-ai-slim Patch: 1.51.0 CWE-22 416 5 ATLAS
MEDIUM EXPLOIT AVAIL

OpenClaw: path traversal enables arbitrary file read

CVE-2026-25475
6.5
EPSS 0.1%
Data Extraction Privacy Violation Supply Chain Agent Plugin
openclaw CWE-22 4 5 ATLAS 1 incident
MEDIUM

n8n: XSS enables session hijacking

CVE-2026-25054
5.4
EPSS 0.0%
Auth Bypass Code Execution Data Extraction Agent Framework API
n8n CWE-79 16 7 ATLAS
MEDIUM

n8n: XSS enables session hijacking

CVE-2026-25051
5.4
EPSS 0.0%
Code Execution Auth Bypass Data Extraction Agent Framework API
n8n CWE-79 16 6 ATLAS
MEDIUM

sagemaker: security flaw enables exploitation

CVE-2026-1778
5.9
EPSS 0.0%
Supply Chain Code Execution Inference Framework
sagemaker Patch: 3.1.1 CWE-295 51 5 ATLAS
MEDIUM

picklescan: Deserialization enables RCE

GHSA-m7j5-r2p5-c39r
--
Supply Chain DoS Code Execution Framework Model Training Data
picklescan Patch: 1.0.1 CWE-502 3 4 ATLAS
MEDIUM EXPLOIT AVAIL

llama-index-core: DoS causes service disruption

CVE-2025-6208
5.3
EPSS 0.0%
DoS Framework RAG
llama-index-core Patch: 0.12.41 CWE-400 1.1K 4 ATLAS
MEDIUM

agentos-taskweaver: Protection Bypass circumvents security controls

GHSA-gpx9-96j6-pp87
6.5
Prompt Injection Code Execution Auth Bypass Agent Framework Plugin
CWE-693 6 ATLAS
MEDIUM EXPLOIT AVAIL

bentoml: Path Traversal enables file access

CVE-2026-24123
6.5
EPSS 0.0%
Supply Chain Data Extraction Framework Inference
bentoml CWE-22 23 8 ATLAS
MEDIUM

chainlit: IDOR enables unauthorized data access

CVE-2025-68492
4.2
EPSS 0.0%
Auth Bypass Data Leakage Framework Agent
chainlit Patch: 2.8.5 CWE-639 39 7 ATLAS
MEDIUM

n8n: security flaw enables exploitation

CVE-2025-68949
5.3
EPSS 0.0%
Auth Bypass Code Execution Agent Framework
n8n CWE-134 16 4 ATLAS
MEDIUM EXPLOIT AVAIL

BetterDocs: Info Disclosure leaks sensitive data

CVE-2025-14980
6.5
EPSS 0.0%
Data Leakage Data Extraction Auth Bypass API Plugin
CWE-200 7 ATLAS
MEDIUM

n8n: security flaw enables exploitation

CVE-2026-21894
6.5
EPSS 0.0%
Auth Bypass Code Execution Agent Framework
n8n CWE-290 16 6 ATLAS
MEDIUM EXPLOIT AVAIL

monai: Path Traversal enables file access

CVE-2026-21851
5.3
EPSS 0.0%
Supply Chain Code Execution Framework
monai Patch: 1.5.2 CWE-22 105 4 ATLAS
MEDIUM EXPLOIT AVAIL

AI component: Missing Auth allows unauthorized operations

CVE-2025-14371
4.3
EPSS 0.0%
Auth Bypass Plugin API
CWE-862 4 ATLAS
MEDIUM

picklescan: Code Injection enables RCE

GHSA-6556-fwc2-fg2p
--
Supply Chain Code Execution Framework Model
picklescan Patch: 0.0.33 CWE-94 3 6 ATLAS
MEDIUM

picklescan: Code Injection enables RCE

GHSA-cffc-mxrf-mhh4
--
Supply Chain Code Execution Framework Model
picklescan Patch: 0.0.33 CWE-94 3 5 ATLAS
MEDIUM

n8n: security flaw enables exploitation

CVE-2025-68697
5.4
EPSS 0.0%
Code Execution Data Extraction Data Leakage Agent Framework
n8n CWE-269 16 7 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial