AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 377 results — Medium severity
MEDIUM CVE-2025-8917

clearml is vulnerable to Path Traversal through its `safe_extract` function

CVSS 5.8 EPSS 0.0% clearml Patch: 2.0.2 CWE-22
View details
MEDIUM CVE-2025-55556

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVSS 6.5 tensorflow
View details
MEDIUM CVE-2025-55554

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46153

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d,...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46152

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46150

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46149

In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-46148

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-58177

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-6051

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `EnglishNormalizer`...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-58446

xgrammar vulnerable to denial of service by huge enum grammar

EPSS 0.1% xgrammar Patch: 0.1.24 CWE-770
View details
MEDIUM GHSA-q77w-mwjj-7mqx

Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-49gj-c84q-6qm9

Picklescan is missing detection when calling built-in python cProfile.run

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-9w88-8rmg-7g2p

Picklescan is missing detection when calling built-in python cProfile.runctx

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-fqq6-7vqf-w3fg

Picklescan is missing detection when calling built-in python doctest.debug_script

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-3gf5-cxq9-w223

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-j343-8v2j-ff7w

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-m869-42cg-3xwr

Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-p9w7-82w4-7q8m

Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-xp4f-hrf8-rxw7

Picklescan is missing detection when calling built-in python ensurepip._run_pip

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-4whj-rm5r-c2v8

Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof

picklescan Patch: 0.0.30
View details
MEDIUM GHSA-9xph-j2h6-g47v

Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-8r4j-24qv-fmq9

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-cj3c-v495-4xqh

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-7cq8-mj8x-j263

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-6w4w-5w54-rjvr

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-3vg9-h568-4w9m

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-f54q-57x4-jg88

Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-6vqj-c2q5-j97w

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-x696-vm39-cp64

Picklescan has a missing detection when calling built-in python profile.Profile.run

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-g344-hcph-8vgg

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-5qwp-399c-mjwf

Picklescan has a missing detection when calling built-in python trace.Trace.run

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-vv6j-3g6g-2pvj

Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-vr7h-p6mm-wpmh

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-h3qp-7fh3-f8h4

Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers

picklescan Patch: 0.0.28
View details
MEDIUM GHSA-f745-w6jp-hpxx

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-f4x7-rfwp-v3xw

Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-86cj-95qr-2p4f

Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-4r9r-ch6f-vxmx

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM CVE-2025-57749

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive...

CVSS 6.5 n8n
View details
MEDIUM CVE-2025-52478

n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-54952

ExecuTorch integer overflow vulnerability leads to code execution

EPSS 0.2% executorch CWE-680
View details
MEDIUM CVE-2025-44779

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

CVSS 6.6 ollama
View details
MEDIUM CVE-2025-5197

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function,...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM GHSA-r54c-2xmf-2cf3

MS SWIFT Deserialization RCE Vulnerability

CWE-502
View details
MEDIUM CVE-2025-54558

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

CVSS 4.1
View details
MEDIUM CVE-2025-7780

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before...

CVSS 6.5
View details
MEDIUM CVE-2025-51471

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a...

CVSS 6.9 ollama
View details
MEDIUM CVE-2025-51481

Dagster Local File Inclusion vulnerability

CVSS 6.6 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-53621

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace...

CVSS 6.9
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial