AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 58 results — Critical severity, has patchPraisonAI: path traversal exposes full filesystem via agent tools
CVE-2026-35615 PraisonAI: path traversal enables arbitrary file write/RCE
CVE-2026-39305 LiteLLM: auth bypass via JWT cache key collision
CVE-2026-35030 praisonaiagents: sandbox bypass enables full host RCE
CVE-2026-34938 MLflow: RCE via unsanitized model dependency specs
CVE-2025-15379 MLflow: path traversal enables sandbox escape, file overwrite
CVE-2025-15036 n8n: stored XSS enables credential theft via workflow
CVE-2026-33749 n8n: member role steals plaintext HTTP credentials
CVE-2026-33663 TensorFlow: type confusion NPD in tensor conversion
CVE-2026-33660 langflow: Path Traversal enables file access
CVE-2026-33309 mlflow: Path Traversal enables file access
CVE-2025-15031 mcp-atlassian: Path Traversal enables file access
CVE-2026-27825 picklescan: Allowlist Bypass evades input filtering
GHSA-g38g-8gr9-h9xp picklescan: security flaw enables exploitation
GHSA-vvpj-8cmc-gx39 picklescan: Allowlist Bypass evades input filtering
GHSA-7wx9-6375-f5wh mlflow: security flaw enables exploitation
CVE-2026-2635 semantic-kernel: Code Injection enables RCE
CVE-2026-26030 semantic-kernel: Path Traversal enables file access
CVE-2026-25592 ray: Code Injection enables RCE
CVE-2025-62593 keras: Path Traversal enables file access
CVE-2025-12060 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert