AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 512 results — has patchopenclaw: operator scope bypass in phone arm/disarm cmds
GHSA-h2v7-xc88-xx8c MLflow: stored XSS via MLmodel YAML artifact upload
CVE-2026-33865 HuggingFace Transformers: RCE via malicious checkpoint load
CVE-2026-1839 PraisonAI: path traversal exposes full filesystem via agent tools
CVE-2026-35615 PraisonAI: recipe registry path traversal file write
CVE-2026-39308 PraisonAI: recipe path traversal allows arbitrary file write
CVE-2026-39306 PraisonAI: path traversal enables arbitrary file write/RCE
CVE-2026-39305 PraisonAI: Zip Slip enables arbitrary file write / RCE
CVE-2026-39307 OpenClaw: script preflight bypass enables unsafe exec
CVE-2026-34425 kedro-datasets: path traversal enables arbitrary file write
CVE-2026-35492 OpenClaw: PKCE verifier leak enables OAuth token theft
CVE-2026-34511 BentoML: malicious bento archive RCE via Jinja2 SSTI
CVE-2026-35044 BentoML: cmd injection RCE on cloud build infra
CVE-2026-35043 LiteLLM: auth bypass via JWT cache key collision
CVE-2026-35030 LiteLLM: auth bypass allows RCE and full takeover
CVE-2026-35029 vLLM: OOM DoS via unbounded video frame decoding
CVE-2026-34755 vLLM: SSRF in batch API exposes cloud metadata endpoints
CVE-2026-34753 vLLM: DoS via unbounded n parameter causes OOM crash
CVE-2026-34756 OpenClaw: SSRF in marketplace fetch hits internal AI infra
GHSA-9q7v-8mr7-g23p onnx: TOCTOU symlink following enables arbitrary file write
GHSA-q56x-g2fj-4rj6 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert