AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 311 results — Medium severity, no patch
MEDIUM CVE-2025-54558

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

CVSS 4.1
View details
MEDIUM CVE-2025-7780

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before...

CVSS 6.5
View details
MEDIUM CVE-2025-51471

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a...

CVSS 6.9 ollama
View details
MEDIUM CVE-2025-51481

Dagster Local File Inclusion vulnerability

CVSS 6.6 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-53621

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace...

CVSS 6.9
View details
MEDIUM CVE-2025-3933

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-6716

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 6.4
View details
MEDIUM CVE-2025-7021

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login...

CVSS 6.5 operator
View details
MEDIUM CVE-2025-6210

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

CVSS 6.2 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-3044

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

CVSS 5.3 EPSS 0.1% CWE-440
View details
MEDIUM CVE-2025-3264

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-3263

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-52554

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow...

CVSS 4.3 n8n
View details
MEDIUM CVE-2025-45809

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

CVSS 5.4 litellm
View details
MEDIUM CVE-2025-49595

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or...

CVSS 4.9 n8n
View details
MEDIUM CVE-2025-6854

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The...

CVSS 4.3 EPSS 0.1% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to...

CVSS 6.5 EPSS 0.1% vllm CWE-20
View details
MEDIUM CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48887

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file...

CVSS 6.5 EPSS 0.1% vllm CWE-1333
View details
MEDIUM CVE-2025-1194

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the...

CVSS 6.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-46343

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-3730

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation...

CVSS 5.5 EPSS 0.1% pytorch CWE-404
View details
MEDIUM CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is...

CVSS 5.5 pytorch
View details
MEDIUM CVE-2025-31843

Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for...

CVSS 4.3
View details
MEDIUM CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption....

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2953

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of...

CVSS 5.5 EPSS 0.2% pytorch CWE-404
View details
MEDIUM CVE-2024-7046

Open WebUI Allows Viewing of Admin Details

CVSS 4.3 EPSS 0.1% open-webui CWE-475
View details
MEDIUM CVE-2024-7045

Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read

CVSS 4.3 EPSS 0.1% open-webui CWE-862
View details
MEDIUM CVE-2024-7035

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)

CVSS 6.9 EPSS 0.0% open-webui CWE-352
View details
MEDIUM CVE-2024-7044

Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload

CVSS 6.8 EPSS 0.3% open-webui CWE-79
View details
MEDIUM CVE-2024-7034

Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint

CVSS 6.5 EPSS 3.0% open-webui CWE-22
View details
MEDIUM CVE-2024-7033

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS 6.5 EPSS 1.2% open-webui CWE-29
View details
MEDIUM GHSA-564p-rx2q-4c8v

BentoML Open Redirect vulnerability

CVSS 6.1 bentoml CWE-601
View details
MEDIUM CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be...

CVSS 5.5 EPSS 0.1% mlflow CWE-521
View details
MEDIUM CVE-2024-8021

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited...

CVSS 6.1 EPSS 2.7% gradio CWE-601
View details
MEDIUM CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment...

CVSS 5.3 EPSS 0.1% mlflow CWE-400
View details
MEDIUM CVE-2024-6577

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This...

CVSS 6.3 EPSS 0.1%
View details
MEDIUM CVE-2024-12217

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow...

CVSS 5.3 EPSS 0.1% gradio CWE-22
View details
MEDIUM CVE-2025-29770

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding)....

CVSS 6.5 EPSS 0.3% vllm CWE-770
View details
MEDIUM CVE-2024-13698

The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and...

CVSS 6.5
View details
MEDIUM CVE-2024-53526

Composio Command Execution vulnerability

CVSS 6.4 EPSS 0.8% CWE-77
View details
MEDIUM CVE-2024-55459

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

CVSS 6.5 EPSS 0.1% keras CWE-22
View details
MEDIUM CVE-2024-11896

The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in all versions up to,...

CVSS 6.4
View details
MEDIUM CVE-2024-52524

ReDoS in giskard's transformation.py (GHSL-2024-324)

EPSS 1.5% CWE-1333
View details
MEDIUM CVE-2024-51751

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file...

CVSS 6.5 EPSS 0.3% gradio CWE-22
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial