AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
UNKNOWN CVE-2026-2492

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of...

Code Execution Auth Bypass Framework RAG Plugin
CWE-427
View details
HIGH CVE-2026-2033

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

Data Extraction Model Poisoning Code Execution Framework RAG Model
CVSS 8.1 EPSS 9.2% mlflow Patch: 3.8.0rc0 CWE-22
View details
HIGH CVE-2026-2472

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

EPSS 0.1% CWE-79
View details
MEDIUM CVE-2026-27482

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

CVSS 5.9 EPSS 0.0% ray Patch: 2.54.0 CWE-306
View details
LOW GHSA-83pf-v6qq-pwmr

Fickling has a detection bypass via stdlib network-protocol constructors

fickling Patch: 0.1.8 CWE-184
View details
HIGH CVE-2026-26286

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions...

Data Extraction Code Execution Social Engineering Framework RAG Agent
CVSS 8.5 CWE-918
View details
CRITICAL CVE-2026-26030

Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution

CVSS 10.0 EPSS 0.1% semantic-kernel Patch: 1.39.4 CWE-94
View details
MEDIUM CVE-2025-12343

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple...

Code Execution Auth Bypass DoS Framework RAG Model
CVSS 5.5
View details
HIGH GHSA-97f8-7cmv-76j2

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

picklescan Patch: 1.0.3 CWE-184
View details
CRITICAL CVE-2026-2654

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to...

CVSS 9.8 smolagents
View details
HIGH CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose...

Data Extraction Code Execution Framework RAG API
CVSS 7.5 EPSS 0.0% keras CWE-73
View details
MEDIUM CVE-2026-26019

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting...

Data Extraction Framework RAG Agent
CVSS 4.1 langchain_community CWE-918
View details
LOW CVE-2026-26013

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation...

Data Extraction Framework RAG Agent
CVSS 3.7 EPSS 0.0% langchain_core CWE-918
View details
MEDIUM CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send...

Code Execution Social Engineering Agent RAG API
CVSS 6.5 n8n CWE-20
View details
CRITICAL CVE-2026-25592

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic...

CVSS 9.9 EPSS 0.1% semantic-kernel Patch: 1.39.3 CWE-22
View details
HIGH CVE-2026-25580

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic...

CVSS 8.6 EPSS 0.0% pydantic-ai Patch: 1.56.0 CWE-918
View details
MEDIUM CVE-2026-25640

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an...

CVSS 5.4 EPSS 0.0% pydantic-ai Patch: 1.51.0 CWE-22
View details
HIGH CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The...

Code Execution Social Engineering Agent RAG API
CVSS 7.2 n8n CWE-20
View details
CRITICAL CVE-2026-25115

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and...

CVSS 9.9 n8n CWE-693
View details
HIGH CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or...

CVSS 8.8 n8n CWE-434
View details
HIGH CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating...

CVSS 8.1 n8n CWE-22
View details
MEDIUM CVE-2026-25054

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface,...

CVSS 5.4 n8n CWE-79
View details
CRITICAL CVE-2026-25053

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to...

CVSS 9.9 n8n CWE-78
View details
CRITICAL CVE-2026-25052

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify...

CVSS 9.9 n8n CWE-367
View details
MEDIUM CVE-2026-25051

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP...

CVSS 5.4 n8n CWE-79
View details
CRITICAL CVE-2026-25049

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in...

CVSS 9.9 n8n CWE-913
View details
HIGH CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to...

CVSS 7.7 n8n CWE-200
View details
HIGH CVE-2026-1777

SageMaker Python SDK has Exposed HMAC

CVSS 7.2 EPSS 0.0% sagemaker Patch: 3.2.0 CWE-201
View details
MEDIUM CVE-2026-1778

SageMaker Python SDK has Insecure TLS Configuration

CVSS 5.9 EPSS 0.0% sagemaker Patch: 3.1.1 CWE-295
View details
CRITICAL CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns...

CVSS 9.8 EPSS 0.1% vllm CWE-532
View details
MEDIUM GHSA-m7j5-r2p5-c39r

picklescan vulnerable to arbitrary file create using logging.FileHandler

picklescan Patch: 1.0.1 CWE-502
View details
HIGH GHSA-9m3x-qqw2-h32h

picklescan missing detection by simple obfuscation of a `builtins.eval` call

picklescan Patch: 1.0.1 CWE-502
View details
CRITICAL CVE-2026-25481

Langroid has WAF Bypass Leading to RCE in TableChatAgent

EPSS 0.0% CWE-94
View details
MEDIUM CVE-2025-6208

llama-index-core vulnerable to Uncontrolled Resource Consumption

CVSS 5.3 EPSS 0.0% llama-index-core Patch: 0.12.41 CWE-400
View details
HIGH CVE-2026-1117

Lollms has an Improper Access Control vulnerability

CVSS 8.2 EPSS 0.1% lollms Patch: 2.1.0 CWE-284
View details
HIGH CVE-2026-0599

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The...

CVSS 7.5 EPSS 0.2% CWE-400
View details
HIGH CVE-2025-10279

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with...

CVSS 7.0 EPSS 0.0% mlflow Patch: 3.4.0rc0 CWE-379
View details
CRITICAL CVE-2026-25130

CAI find_file Agent Tool has Command Injection Vulnerability Through Argument Injection

CVSS 9.7 EPSS 0.0% CWE-78
View details
LOW CVE-2026-25211

Llama Stack exposes secret in initialization log

CVSS 3.2 EPSS 0.0% CWE-532
View details
HIGH CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT...

CVSS 8.8 EPSS 0.1% CWE-94
View details
MEDIUM GHSA-gpx9-96j6-pp87

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF)

CVSS 6.5 CWE-693
View details
HIGH CVE-2026-24779

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the...

CVSS 7.1 EPSS 0.0% vllm CWE-918
View details
HIGH CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file...

CVSS 8.8 EPSS 0.0% pytorch CWE-94
View details
CRITICAL CVE-2026-1470

n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be...

CVSS 9.9 n8n CWE-95
View details
MEDIUM CVE-2026-24123

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentofile.yaml` configuration allows path traversal...

CVSS 6.5 EPSS 0.0% bentoml CWE-22
View details
CRITICAL CVE-2025-13374

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3....

CVSS 9.8 CWE-434
View details
UNKNOWN CVE-2026-0772

Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow....

langflow CWE-502
View details
UNKNOWN CVE-2026-0771

Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Attack vectors...

langflow CWE-94
View details
HIGH CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

EPSS 11.4% langflow CWE-829
View details
UNKNOWN CVE-2026-0769

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow....

langflow CWE-95
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial