AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

230

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
HIGH

open-webui: auth bypass allows unrestricted model access

CVE-2026-44556
7.1
Auth Bypass DoS Data Extraction API Inference Model
open-webui Patch: 0.9.0 CWE-284 8 ATLAS
HIGH

open-webui: access control bypass via model chaining

CVE-2026-44555
7.6
Auth Bypass API Model Inference
open-webui Patch: 0.9.0 CWE-862 4 ATLAS
HIGH

open-webui: Redis cache poisoning enables cross-instance tool hijack

CVE-2026-44552
8.7
Supply Chain Data Extraction Prompt Injection Agent Plugin Framework
open-webui Patch: 0.9.0 CWE-668 6 ATLAS
HIGH

open-webui: stale Socket.IO role allows cross-user note R/W

CVE-2026-44553
8.1
Auth Bypass Data Extraction Privacy Violation API Framework
open-webui Patch: 0.9.0 CWE-384 5 ATLAS
MEDIUM

open-webui: mass assignment enables cross-user folder injection

CVE-2026-44550
5.0
Auth Bypass Social Engineering Privacy Violation Framework API
open-webui Patch: 0.9.0 CWE-862 4 ATLAS
CRITICAL

open-webui: LDAP auth bypass — full account takeover

CVE-2026-44551
9.1
Auth Bypass Data Extraction Framework API
open-webui Patch: 0.9.0 CWE-287 4 ATLAS
HIGH

open-webui: XSS in model descriptions steals session tokens

CVE-2026-44721
7.3
Auth Bypass Code Execution Data Extraction API Framework
open-webui Patch: 0.9.0 CWE-79 5 ATLAS
HIGH

n8n-mcp: path traversal + SSRF exposes n8n API keys

GHSA-8g7g-hmwm-6rv2
8.3
Auth Bypass Data Extraction Data Leakage Agent Plugin
n8n-mcp Patch: 2.50.1 CWE-22 16 6 ATLAS
AWAITING NVD

n8n-MCP: SSRF allows internal network access via webhook tools

CVE-2026-44694
--
EPSS 0.0%
Data Extraction Prompt Injection Auth Bypass Agent Plugin
n8n-mcp Patch: 2.50.2 CWE-367 16 5 ATLAS
HIGH

LiteLLM: RCE via MCP test endpoint command injection

CVE-2026-42271
8.8
EPSS 0.1%
Code Execution Auth Bypass Framework API Inference
litellm CWE-77 4 5 ATLAS
CRITICAL EXPLOIT ACTIVE

LiteLLM: SQL injection exposes LLM API credentials

CVE-2026-42208
9.8
EPSS 37.4%
Auth Bypass Data Extraction Supply Chain API Inference
litellm CWE-89 4 5 ATLAS
AWAITING NVD

LiteLLM: SSTI in prompt template endpoint enables RCE

CVE-2026-42203
--
EPSS 0.0%
Code Execution Data Extraction API Inference
litellm CWE-1336 4 5 ATLAS
MEDIUM

BentoML: symlink traversal exfiltrates host secrets at build

CVE-2026-40610
5.5
Data Extraction Supply Chain Framework
bentoml Patch: 1.4.39 CWE-59 23 4 ATLAS
HIGH

diffusers: trust_remote_code bypass enables silent RCE

CVE-2026-44513
8.8
Supply Chain Code Execution Framework Model
diffusers Patch: 0.38.0 CWE-94 392 4 ATLAS
CRITICAL

vm2: sandbox escape via nesting:true enables RCE

CVE-2026-44007
9.1
Code Execution Auth Bypass Agent Framework
vm2 Patch: 3.11.1 CWE-284 1.5K 5 ATLAS
HIGH

diffusers: silent RCE via None.py trust_remote_code bypass

GHSA-j7w6-vpvq-j3gm
8.8
Code Execution Supply Chain Framework Model
diffusers Patch: 0.38.0 CWE-94 392 6 ATLAS
HIGH

Aegra: cross-tenant IDOR hijacks user thread data

CVE-2026-44504
--
Auth Bypass Data Extraction Data Leakage Framework Agent
aegra-api Patch: 0.9.7 CWE-285 3.1K 5 ATLAS
CRITICAL

pytorch-lightning: supply chain, credential harvesting

CVE-2026-44484
--
Supply Chain Data Extraction Code Execution Framework
pytorch-lightning CWE-506 1.6K 5 ATLAS
MEDIUM

vercel: auth token leak in AI agent non-interactive mode

CVE-2026-44479
5.5
Data Leakage Auth Bypass Agent API
CWE-200 5 ATLAS
MEDIUM

@axonflow/openclaw: credential exposure via insecure file permissions

GHSA-cqmh-pcgr-q42f
5.5
Data Leakage Auth Bypass Privacy Violation Plugin Agent
@axonflow/openclaw Patch: 2.0.0 CWE-552 4 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial