AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 199 results — High severity, has patchJupyterLab: Extension allow-list bypass enables privesc
CVE-2026-42266 openclaw: Model bypasses authz to persist unsafe config
GHSA-cwj3-vqpp-pmxr OpenClaw: RCE via malicious repo setup-api.js
GHSA-r39h-4c2p-3jxp Jupyter Server: CORS bypass via regex anchor omission
CVE-2026-40110 Jupyter Server: path traversal leaks sibling directories
CVE-2026-35397 openclaw: TOCTOU sandbox escape via symlink swap
GHSA-wppj-c6mr-83jj openclaw: MCP owner-context spoofing, privilege escalation
GHSA-r6xh-pqhr-v4xh n8n-mcp: SSRF bypass via IPv6 leaks API keys
CVE-2026-42449 Jupyter Notebook: stored XSS enables full account takeover
CVE-2026-40171 marked: infinite recursion DoS crashes Node.js via OOM
CVE-2026-41680 litellm: RCE via MCP test endpoints privilege bypass
GHSA-v4p8-mg3p-g94g Claude Code: git worktree trust bypass executes hooks
CVE-2026-40068 Ray: Parquet RCE via Arrow extension deserialization
CVE-2026-41486 LiteLLM: RCE via unsandboxed prompt template rendering
GHSA-xqmj-j6mv-4862 Claude Code: sandbox escape via symlink allows arbitrary write
CVE-2026-39861 A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file...
CVE-2026-6596 OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
GHSA-mr34-9552-qr95 OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
GHSA-2gvc-4f3c-2855 OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
GHSA-xmxx-7p24-h892 PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
GHSA-rg3h-x3jw-7jm5 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert