AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

226

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
MEDIUM

OpenClaw: path traversal → host file exfiltration via QQ Bot

GHSA-846p-hgpv-vphc
--
Prompt Injection Data Extraction Agent Plugin
openclaw Patch: 2026.4.2 CWE-22 4 4 ATLAS 1 incident
MEDIUM

openclaw: path traversal enables remote dir overwrite

GHSA-m34q-h93w-vg5x
--
Supply Chain Code Execution Agent Framework
openclaw Patch: 2026.4.2 CWE-22 4 4 ATLAS 1 incident
LOW

OpenClaw: cross-account webhook event suppression

GHSA-fqrj-m88p-qf3v
--
DoS Auth Bypass Agent
openclaw Patch: 2026.3.31 CWE-287 4 3 ATLAS
MEDIUM

OpenClaw: pairing DoS blocks account onboarding

GHSA-wwfp-w96m-c6x8
--
DoS Agent
openclaw Patch: 2026.3.31 4 2 ATLAS 1 incident
MEDIUM

OpenClaw: pre-auth signature bypass enables pairing DoS

GHSA-h43v-27wg-5mf9
--
DoS Auth Bypass Agent Framework
openclaw Patch: 2026.3.31 CWE-347 4 3 ATLAS
MEDIUM

OpenClaw: exec allowlist bypass via shell init-file options

GHSA-wpc6-37g7-8q4w
--
Auth Bypass Code Execution Agent Plugin
openclaw Patch: 2026.3.31 CWE-184 4 4 ATLAS 1 incident
MEDIUM

openclaw: sandbox escape via mirror mode hook execution

GHSA-42mx-vp8m-j7qh
--
Code Execution Supply Chain Agent Framework
openclaw Patch: 2026.3.28 CWE-829 4 4 ATLAS 1 incident
LOW

openclaw: operator.write escalates to admin Telegram config + cron

GHSA-767m-xrhc-fxm7
--
Auth Bypass Data Leakage Agent
openclaw Patch: 2026.3.28 CWE-269 4 4 ATLAS 1 incident
MEDIUM

openclaw: auth bypass exposes agent session visibility

GHSA-fwjq-xwfj-gv75
--
Auth Bypass Data Extraction Agent Framework
openclaw Patch: 2026.3.31 CWE-863 4 4 ATLAS 1 incident
MEDIUM

openclaw: privilege escalation to admin voice config persistence

GHSA-3q42-xmxv-9vfr
--
Auth Bypass Supply Chain Agent Framework
openclaw Patch: 2026.3.28 CWE-269 4 3 ATLAS 1 incident
HIGH

openclaw: env var injection via workspace config

GHSA-vfw7-6rhc-6xxg
--
Supply Chain Code Execution Data Extraction Agent Framework Plugin
openclaw Patch: 2026.3.24 CWE-426 4 4 ATLAS 1 incident
MEDIUM

openclaw: SSRF in marketplace plugin download

GHSA-vjx8-8p7h-82gr
--
Supply Chain Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.3.31 CWE-918 4 4 ATLAS 1 incident
MEDIUM

openclaw: media download bypass exhausts disk storage

GHSA-4g5x-2jfc-xm98
--
DoS Agent Plugin
openclaw Patch: 2026.3.31 CWE-434 4 3 ATLAS
MEDIUM

openclaw: operator scope bypass in phone arm/disarm cmds

GHSA-h2v7-xc88-xx8c
--
Auth Bypass Agent Plugin
openclaw Patch: 2026.3.28 CWE-285 4 3 ATLAS 1 incident
HIGH EXPLOIT AVAIL

text-generation-webui: unauthenticated path traversal file read

CVE-2026-35485
7.5
EPSS 0.4%
Data Extraction Auth Bypass Inference Framework
gradio CWE-22 679 3 ATLAS
MEDIUM EXPLOIT AVAIL

MLflow: auth bypass exposes model artifacts across experiments

CVE-2026-33866
--
EPSS 0.0%
Auth Bypass Data Extraction Framework Model
mlflow CWE-862 624 4 ATLAS
MEDIUM EXPLOIT AVAIL

MLflow: stored XSS via MLmodel YAML artifact upload

CVE-2026-33865
--
EPSS 0.0%
Code Execution Auth Bypass Data Extraction Framework Model
mlflow Patch: 3.11.1 CWE-79 624 4 ATLAS
MEDIUM EXPLOIT AVAIL

HuggingFace Transformers: RCE via malicious checkpoint load

CVE-2026-1839
6.5
EPSS 0.0%
Code Execution Supply Chain Framework Training Data
transformers Patch: 5.0.0rc3 CWE-502 7.9K 3 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: path traversal exposes full filesystem via agent tools

CVE-2026-35615
--
EPSS 0.1%
Data Extraction Code Execution Agent Framework
PraisonAI Patch: 1.5.113 CWE-22 1 5 ATLAS
HIGH EXPLOIT AVAIL

PraisonAI: recipe registry path traversal file write

CVE-2026-39308
7.1
EPSS 0.1%
Supply Chain Code Execution Agent Framework
PraisonAI Patch: 4.5.113 CWE-22 1 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial