AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 24 of 74 results — High severity, has patch
HIGH CVE-2025-58755

MONAI does not prevent path traversal, potentially leading to arbitrary file writes

CVSS 8.8 EPSS 0.1% monai Patch: 1.5.1 CWE-22
View details
HIGH CVE-2025-6984

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The...

CVSS 7.5 EPSS 2.1% langchain-community Patch: 0.3.27 CWE-200
View details
HIGH CVE-2025-5302

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

CVSS 8.6 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
HIGH CVE-2025-57809

XGrammar affected by Denial of Service by infinite recursion grammars

CVSS 7.5 EPSS 0.0% xgrammar Patch: 0.1.21 CWE-674
View details
HIGH CVE-2025-9141

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

CVSS 8.8 vllm Patch: 0.10.1.1 CWE-502
View details
HIGH GHSA-9gvj-pp9x-gcfr

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

picklescan Patch: 0.0.27 CWE-502
View details
HIGH CVE-2025-30402

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

CVSS 8.1 EPSS 0.1% executorch Patch: 0.7.0-rc1 CWE-122
View details
HIGH CVE-2025-6209

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS 7.5 EPSS 0.1% llama-index-core Patch: 0.12.41 CWE-29
View details
HIGH CVE-2025-47783

label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

EPSS 0.2% label-studio Patch: 1.18.0 CWE-79
View details
HIGH CVE-2025-1752

LlamaIndex Vulnerable to Denial of Service (DoS)

CVSS 7.5 EPSS 0.2% llama-index Patch: 0.12.21 CWE-400
View details
HIGH CVE-2025-46567

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script...

CVSS 7.8 EPSS 0.2% llamafactory Patch: 0.9.3 CWE-502
View details
HIGH CVE-2025-46417

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

EPSS 0.2% picklescan Patch: 0.0.25 CWE-184
View details
HIGH CVE-2025-0628

LiteLLM Has an Improper Authorization Vulnerability

CVSS 8.1 EPSS 0.1% litellm Patch: 1.61.15 CWE-266
View details
HIGH CVE-2024-9606

LiteLLM Reveals Portion of API Key via a Logging File

CVSS 7.5 EPSS 0.1% litellm Patch: 1.44.12 CWE-117
View details
HIGH CVE-2024-8984

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

CVSS 7.5 EPSS 0.2% litellm Patch: 1.56.2 CWE-400
View details
HIGH CVE-2024-8060

Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions

CVSS 8.1 EPSS 0.9% open-webui Patch: 0.5.17 CWE-22
View details
HIGH CVE-2024-7776

Open Neural Network Exchange (ONNX) Path Traversal Vulnerability

CVSS 8.1 EPSS 1.5% onnx Patch: 1.17.0 CWE-22
View details
HIGH CVE-2024-7806

Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability

CVSS 8.0 EPSS 0.7% open-webui Patch: 0.3.33 CWE-352
View details
HIGH GHSA-6wj5-5pgr-jwq8

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file

CVSS 7.5 open-webui Patch: 0.4.7 CWE-400
View details
HIGH CVE-2024-6982

LoLLMS Code Injection vulnerability

CVSS 8.4 EPSS 0.1% lollms Patch: 11.0.0 CWE-94
View details
HIGH CVE-2024-10188

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function...

CVSS 7.5 EPSS 0.1% litellm Patch: 1.53.1.dev1 CWE-400
View details
HIGH CVE-2025-25297

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

CVSS 8.6 EPSS 0.2% label-studio Patch: 1.16.0 CWE-918
View details
HIGH CVE-2024-5187

onnx allows Arbitrary File Overwrite in download_model_with_test_data

CVSS 8.8 EPSS 1.4% onnx Patch: 1.16.2 CWE-22
View details
HIGH CVE-2018-8768

Jupyter Notebook file bypasses sanitization, executes JavaScript

CVSS 7.8 EPSS 0.1% notebook Patch: 5.4.1
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial