AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 512 results — has patch
MEDIUM

open-webui: mass assignment enables cross-user folder injection

CVE-2026-44550
5.0
Auth Bypass Social Engineering Privacy Violation Framework API
open-webui Patch: 0.9.0 CWE-862 4 ATLAS
CRITICAL

open-webui: LDAP auth bypass — full account takeover

CVE-2026-44551
9.1
Auth Bypass Data Extraction Framework API
open-webui Patch: 0.9.0 CWE-287 4 ATLAS
HIGH

open-webui: XSS in model descriptions steals session tokens

CVE-2026-44721
7.3
Auth Bypass Code Execution Data Extraction API Framework
open-webui Patch: 0.9.0 CWE-79 5 ATLAS
HIGH

n8n-mcp: path traversal + SSRF exposes n8n API keys

GHSA-8g7g-hmwm-6rv2
8.3
Auth Bypass Data Extraction Data Leakage Agent Plugin
n8n-mcp Patch: 2.50.1 CWE-22 16 6 ATLAS
UNKNOWN

n8n-MCP: SSRF allows internal network access via webhook tools

CVE-2026-44694
--
EPSS 0.0%
Data Extraction Prompt Injection Auth Bypass Agent Plugin
n8n-mcp Patch: 2.50.2 CWE-367 16 5 ATLAS
MEDIUM

BentoML: symlink traversal exfiltrates host secrets at build

CVE-2026-40610
5.5
Data Extraction Supply Chain Framework
bentoml Patch: 1.4.39 CWE-59 23 4 ATLAS
HIGH

diffusers: trust_remote_code bypass enables silent RCE

CVE-2026-44513
8.8
Supply Chain Code Execution Framework Model
diffusers Patch: 0.38.0 CWE-94 392 4 ATLAS
CRITICAL

vm2: sandbox escape via nesting:true enables RCE

CVE-2026-44007
9.1
Code Execution Auth Bypass Agent Framework
vm2 Patch: 3.11.1 CWE-284 1.5K 5 ATLAS
HIGH

diffusers: silent RCE via None.py trust_remote_code bypass

GHSA-j7w6-vpvq-j3gm
8.8
Code Execution Supply Chain Framework Model
diffusers Patch: 0.38.0 CWE-94 392 6 ATLAS
HIGH

Aegra: cross-tenant IDOR hijacks user thread data

CVE-2026-44504
--
Auth Bypass Data Extraction Data Leakage Framework Agent
aegra-api Patch: 0.9.7 CWE-285 3.1K 5 ATLAS
MEDIUM

@axonflow/openclaw: credential exposure via insecure file permissions

GHSA-cqmh-pcgr-q42f
5.5
Data Leakage Auth Bypass Privacy Violation Plugin Agent
@axonflow/openclaw Patch: 2.0.0 CWE-552 4 5 ATLAS
HIGH

praisonai: RCE via unpatched tool_override exec_module

CVE-2026-44334
8.4
EPSS 0.0%
Code Execution Auth Bypass Supply Chain Agent Framework Plugin
praisonai Patch: 4.6.32 CWE-94 1 5 ATLAS
HIGH

praisonaiagents: SSRF via URL parser confusion bypass

CVE-2026-44335
--
EPSS 0.0%
Auth Bypass Data Extraction Agent Plugin
praisonaiagents Patch: 1.6.32 CWE-918 11 4 ATLAS
HIGH

GitPython: git config injection enables hook RCE

CVE-2026-44244
7.8
EPSS 0.0%
Supply Chain Code Execution Framework
GitPython Patch: 3.1.49 CWE-94 81 3 ATLAS
MEDIUM

vLLM: speculative decoding DoS via penalty params

CVE-2026-44223
6.5
DoS Inference
vllm Patch: 0.20.0 CWE-131 127 2 ATLAS
HIGH

JupyterLab: one-click RCE via notebook HTML cell output

CVE-2026-42557
--
Code Execution Social Engineering Supply Chain Framework Plugin
notebook Patch: 7.5.6 CWE-79 2.9K 8 ATLAS
HIGH

mistune: ReDoS exposes Jupyter/AI services to DoS

CVE-2026-33079
--
EPSS 0.0%
DoS Supply Chain Framework API
mistune Patch: 3.2.1 CWE-1333 1.9K 4 ATLAS
MEDIUM

vLLM: token injection DoS via multimodal placeholders

CVE-2026-44222
6.5
DoS Prompt Injection Inference Model Framework
vllm Patch: 0.20.0 CWE-129 127 5 ATLAS
HIGH

JupyterLab: Extension allow-list bypass enables privesc

CVE-2026-42266
8.8
Supply Chain Auth Bypass Code Execution Framework Plugin
jupyterlab Patch: 4.5.7 CWE-20 1.9K 4 ATLAS
HIGH

openclaw: Model bypasses authz to persist unsafe config

GHSA-cwj3-vqpp-pmxr
8.8
Prompt Injection Auth Bypass Code Execution Agent Plugin Framework
openclaw Patch: 2026.4.23 CWE-862 4 5 ATLAS 1 incident

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial