AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1624 resultsLangflow: IDOR exposes flows and plaintext API keys
CVE-2026-34046 Langflow: server-side RCE via LLM-generated code exec
CVE-2026-33873 DOMPurify: mXSS bypass achieves XSS via parse-context switch
GHSA-h8r8-wccr-v5f2 langchain-core: path traversal exposes host secrets via prompt config
CVE-2026-34070 @mobilenext/mobile-mcp: path traversal via AI agent tool
CVE-2026-33989 n8n: stored XSS via malicious OAuth2 Authorization URL
GHSA-364x-8g5j-x2pr n8n: Stored XSS in Chat Trigger via CSS injection
GHSA-3c7f-5hgj-h279 n8n: stored XSS enables phishing via Form Node
GHSA-w673-8fjw-457c n8n: Stored XSS in Form Trigger enables phishing
GHSA-q4fm-pjq6-m63g smolagents: code injection via incomplete sandbox fix
CVE-2026-4963 MLflow: broken access control exposes experiment traces
CVE-2025-15381 Open WebUI: IDOR exposes AI memories and private files
CVE-2026-29071 open-webui: missing authz allows cross-KB file deletion
CVE-2026-29070 Open WebUI: BOLA enables RAG poisoning via file overwrite
CVE-2026-28788 Open WebUI: path traversal leaks server filesystem path
CVE-2026-28786 BentoML: command injection in bentofile.yaml containerize
CVE-2026-33744 vLLM: trust_remote_code bypass enables RCE
CVE-2026-27893 Streamlit: SSRF leaks NTLMv2 creds via UNC path
CVE-2026-33682 n8n: LDAP injection enables auth bypass in workflows
CVE-2026-33751 n8n: stored XSS enables credential theft via workflow
CVE-2026-33749 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert