AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severityLangchain-Chatchat: path traversal in file API exposes host FS
CVE-2025-6854 n8n: open redirect enables phishing via login flow
CVE-2025-49592 MLflow: unauthenticated SSRF in gateway proxy
CVE-2025-52967 vLLM: input validation DoS crashes inference worker
CVE-2025-48944 vLLM: ReDoS crashes inference server via malformed regex
CVE-2025-48943 vLLM: DoS via malformed JSON schema guided param
CVE-2025-48942 vLLM: ReDoS in tool parser causes service outage
CVE-2025-48887 vllm: ReDoS in inference endpoints enables DoS
GHSA-j828-28rj-hfhp transformers: ReDoS in GPT-NeoX Japanese tokenizer
CVE-2025-1194 n8n: stored XSS enables account takeover
CVE-2025-46343 PyTorch: DoS via ctc_loss resource mishandling
CVE-2025-3730 vLLM: DoS via unbounded XGrammar schema cache
GHSA-hf3c-wxg2-49q9 xgrammar: unbounded grammar cache causes LLM server DoS
CVE-2025-32381 picklescan: bypass allows silent RCE in ML pipelines
GHSA-v7x6-rv5q-mhwc picklescan: numpy bypass enables RCE in ML model pipelines
GHSA-fj43-3qmq-673f PyTorch: memory corruption in JIT flatbuffer loader
CVE-2025-3121 OpenAI WP Plugin: broken access control on AI settings
CVE-2025-31843 PyTorch: lstm_cell memory corruption, local code exec
CVE-2025-3001 PyTorch: memory corruption in torch.jit.script compiler
CVE-2025-3000 PyTorch: memory corruption in RNN sequence unpacking
CVE-2025-2999 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert