AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 524 results — High severity
HIGH CVE-2026-22773

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3...

CVSS 7.5 EPSS 0.0% vllm CWE-770
View details
HIGH CVE-2026-22612

Fickling vulnerable to detection bypass due to "builtins" blindness

EPSS 0.1% fickling Patch: 0.1.7 CWE-502
View details
HIGH CVE-2026-22609

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22608

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

EPSS 0.0% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22607

Fickling Blocklist Bypass: cProfile.run()

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22606

Fickling has a bypass via runpy.run_path() and runpy.run_module()

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
HIGH GHSA-mcmc-2m55-j8jj

vLLM introduced enhanced protection for CVE-2025-62164

CVSS 8.8 vllm Patch: 0.13.0 CWE-20
View details
HIGH GHSA-9726-w42j-3qjr

picklescan has Arbitrary file read using `io.FileIO`

picklescan Patch: 0.0.35 CWE-22
View details
HIGH CVE-2026-0621

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded...

CVSS 7.5
View details
HIGH GHSA-46h3-79wf-xr6c

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter

picklescan Patch: 0.0.34 CWE-94
View details
HIGH GHSA-955r-x9j8-7rhh

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller

picklescan Patch: 0.0.34 CWE-94
View details
HIGH GHSA-rrxm-2pvv-m66x

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-3329-ghmp-jmv5

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-x843-g5mx-g377

Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-r8g5-cgf2-4m4m

Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef

picklescan Patch: 0.0.33 CWE-502
View details
HIGH GHSA-hgrh-qx5j-jfwx

Picklescan Bypasses Unsafe Globals Check using pty.spawn

CVSS 8.8 picklescan Patch: 0.0.33 CWE-693
View details
HIGH GHSA-vqmv-47xg-9wpr

Picklescan missing detection when calling pty.spawn

picklescan Patch: 0.0.33 CWE-502
View details
HIGH GHSA-84r2-jw7c-4r5q

Picklescan has Incomplete List of Disallowed Inputs

picklescan Patch: 0.0.33 CWE-184
View details
HIGH GHSA-4675-36f9-wf6r

Picklescan does not block ctypes

picklescan Patch: 0.0.33 CWE-184
View details
HIGH GHSA-m273-6v24-x4m4

Picklescan vulnerable to Arbitrary File Writing

picklescan Patch: 0.0.33 CWE-502
View details
HIGH CVE-2025-67729

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

CVSS 8.8 EPSS 0.1% CWE-502
View details
HIGH CVE-2025-68664

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd()...

CVSS 8.2 EPSS 0.0% langchain_core CWE-502
View details
HIGH ACTIVELY EXPLOITED CVE-2025-68613

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their...

CVSS 8.8 n8n CWE-913
View details
HIGH CVE-2025-68478

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the...

CVSS 7.1 EPSS 0.1% langflow CWE-73
View details
HIGH CVE-2025-53000

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

EPSS 0.0% CWE-427
View details
HIGH CVE-2025-67748

Fickling has Code Injection vulnerability via pty.spawn()

EPSS 0.0% fickling Patch: 0.1.6 CWE-94
View details
HIGH CVE-2025-67747

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

EPSS 0.1% fickling Patch: 0.1.6 CWE-184
View details
HIGH CVE-2025-67644

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

CVSS 7.3 EPSS 0.0% CWE-89
View details
HIGH CVE-2025-33213

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to...

CVSS 8.8 CWE-502
View details
HIGH CVE-2025-65964

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation...

CVSS 8.8 n8n
View details
HIGH CVE-2025-34291

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with...

CVSS 8.8 EPSS 13.1% langflow CWE-346
View details
HIGH CVE-2025-65958

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

CVSS 8.5 EPSS 0.0% open-webui Patch: 0.6.37 CWE-918
View details
HIGH CVE-2025-66404

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes...

CVSS 8.8
View details
HIGH CVE-2025-66448

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm...

CVSS 8.8 EPSS 0.2% vllm CWE-94
View details
HIGH CVE-2025-65106

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template...

EPSS 0.1% langchain-core Patch: 1.0.7 CWE-1336
View details
HIGH CVE-2025-62609

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer...

CVSS 7.5 EPSS 0.1% mlx CWE-476
View details
HIGH CVE-2025-12973

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function...

CVSS 7.2
View details
HIGH CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and...

CVSS 8.8 EPSS 0.1% vllm CWE-20
View details
HIGH CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

CVSS 7.3 EPSS 0.2% open-webui Patch: 0.6.35 CWE-95
View details
HIGH CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

CVSS 8.7 EPSS 0.0% open-webui Patch: 0.6.35 CWE-79
View details
HIGH CVE-2025-64439

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

EPSS 0.8% CWE-502
View details
HIGH CVE-2025-62726

n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n....

CVSS 8.8 n8n
View details
HIGH CVE-2025-64104

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

CVSS 7.3 EPSS 0.1% CWE-89
View details
HIGH CVE-2025-8709

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10....

CVSS 7.3 EPSS 0.0% CWE-89
View details
HIGH CVE-2025-7707

llama-index has Insecure Temporary File

CVSS 7.1 EPSS 0.0% llama-index Patch: 0.13.0 CWE-377
View details
HIGH CVE-2025-6242

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and...

CVSS 7.1 EPSS 0.0% vllm Patch: 0.11.0 CWE-601
View details
HIGH CVE-2025-61784

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the...

CVSS 8.1 EPSS 0.1% llamafactory Patch: 0.9.4 CWE-918
View details
HIGH CVE-2025-59425

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnerable to a timing...

CVSS 7.5 EPSS 0.4% vllm CWE-385
View details
HIGH CVE-2025-6985

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class...

CVSS 7.5 EPSS 0.2% CWE-611
View details
HIGH CVE-2025-7647

llama-index-core insecurely handles temporary files

CVSS 7.3 EPSS 0.0% llama-index-core Patch: 0.13.0 CWE-378
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial