AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 225 results — Critical severityPraisonAI: auth bypass enables browser session hijack
GHSA-8x8f-54wf-vv92 PraisonAI: RCE via malicious workflow YAML execution
GHSA-vc46-vw85-3wvm PraisonAI: path traversal allows arbitrary file write via recipe unpack
CVE-2026-40157 PraisonAI: supply chain RCE via unverified template exec
CVE-2026-40154 lollms: Stored XSS enables wormable account takeover
CVE-2026-1115 PraisonAI: RCE via shell injection in memory hooks executor
CVE-2026-40111 PraisonAI: RCE via shell injection in agent workflows
GHSA-2763-cj5r-c79m Marimo: pre-auth RCE via terminal WebSocket
GHSA-2679-6mx9-h9xc praisonaiagents: sandbox escape enables host RCE
CVE-2026-39888 PraisonAI: YAML deserialization enables unauthenticated RCE
CVE-2026-39890 PraisonAI: path traversal exposes full filesystem via agent tools
CVE-2026-35615 PraisonAI: path traversal enables arbitrary file write/RCE
CVE-2026-39305 Claude Code: OS command injection, credential theft
CVE-2026-35022 Budibase: Unauthenticated RCE as root via webhook
CVE-2026-35216 LiteLLM: auth bypass via JWT cache key collision
CVE-2026-35030 MLflow: auth bypass in job API enables unauthenticated RCE
CVE-2026-0545 praisonaiagents: sandbox bypass enables full host RCE
CVE-2026-34938 MLflow: command injection via model_uri in mlserver mode
CVE-2026-0596 telnyx: PyPI supply chain attack steals cloud creds
GHSA-955r-262c-33jc MLflow: RCE via unsanitized model dependency specs
CVE-2025-15379 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert