AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1625 resultsltiauthenticator: OAuth nonce leak causes server DoS
CVE-2026-34052 JupyterHub: open redirect enables post-login phishing
CVE-2026-33709 oauthenticator: auth bypass enables JupyterHub account takeover
CVE-2026-33175 MLflow: auth bypass in job API enables unauthenticated RCE
CVE-2026-0545 vLLM: DoS via unbounded n parameter causes OOM crash
CVE-2026-34756 Ajenti: missing authz lets any user install packages
CVE-2026-35175 OpenClaw: SSRF in marketplace fetch hits internal AI infra
GHSA-9q7v-8mr7-g23p vLLM: audio downmix mismatch enables adversarial input
CVE-2026-34760 onnx: TOCTOU symlink following enables arbitrary file write
GHSA-q56x-g2fj-4rj6 praisonaiagents: SSRF leaks cloud IAM credentials
CVE-2026-34954 PraisonAI: sandbox escape via shell=True blocklist bypass
CVE-2026-34955 PraisonAI: SSRF via api_base steals cloud IAM credentials
CVE-2026-34936 PraisonAI: OS command injection via run_python() shell escape
CVE-2026-34937 praisonaiagents: sandbox bypass enables full host RCE
CVE-2026-34938 Open WebUI: access control bypass leaks Tool Valve API keys
CVE-2026-34222 ONNX: symlink traversal reads host files via model loading
CVE-2026-34447 ONNX: hardlink path traversal leaks sensitive files
CVE-2026-34446 ONNX: property overwrite via crafted model file
CVE-2026-34445 ONNX: symlink path traversal allows arbitrary file read
CVE-2026-27489 Anthropic SDK: TOCTOU symlink escape in async memory tool
CVE-2026-34452 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert