AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
UNKNOWN CVE-2026-0768

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not...

langflow CWE-94
View details
UNKNOWN CVE-2025-15063

Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server....

CWE-78
View details
HIGH CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a...

CVSS 7.4 CWE-79
View details
CRITICAL CVE-2026-22807

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model...

CVSS 9.8 EPSS 0.0% vllm CWE-94
View details
HIGH CVE-2026-21852

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before...

CVSS 7.5 claude_code CWE-522
View details
HIGH CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVSS 7.5 ollama
View details
HIGH CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

CVSS 7.5 ollama
View details
HIGH CVE-2025-33233

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution,...

CVSS 7.8 CWE-94
View details
HIGH CVE-2026-22219

Chainlit contain a server-side request forgery (SSRF) vulnerability

CVSS 7.7 EPSS 0.0% chainlit Patch: 2.9.4 CWE-918
View details
CRITICAL CVE-2026-0863

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system....

CVSS 9.9 n8n CWE-94
View details
HIGH CVE-2026-0897

Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component

EPSS 0.0% keras Patch: 3.12.1 CWE-770
View details
MEDIUM CVE-2025-68492

Chainlit contains an authorization bypass vulnerability

CVSS 4.2 EPSS 0.0% chainlit Patch: 2.8.5 CWE-639
View details
MEDIUM CVE-2025-68949

n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a...

CVSS 5.3 n8n CWE-134
View details
HIGH CVE-2025-15514

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data...

CVSS 7.5 ollama CWE-395
View details
HIGH CVE-2024-58340

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method...

CVSS 7.5 langchain CWE-1333
View details
HIGH CVE-2024-58339

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query()...

CVSS 7.5 llamaindex CWE-770
View details
HIGH CVE-2024-14021

LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py....

CVSS 7.8 llamaindex CWE-502
View details
HIGH CVE-2026-22033

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

EPSS 0.0% label-studio CWE-79
View details
HIGH CVE-2025-14279

MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to...

CVSS 8.1 EPSS 0.0% mlflow Patch: 3.5.0 CWE-346
View details
HIGH CVE-2026-22773

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3...

CVSS 7.5 EPSS 0.0% vllm CWE-770
View details
HIGH CVE-2026-22612

Fickling vulnerable to detection bypass due to "builtins" blindness

EPSS 0.1% fickling Patch: 0.1.7 CWE-502
View details
HIGH CVE-2026-22609

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22608

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

EPSS 0.0% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22607

Fickling Blocklist Bypass: cProfile.run()

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
HIGH CVE-2026-22606

Fickling has a bypass via runpy.run_path() and runpy.run_module()

EPSS 0.1% fickling Patch: 0.1.7 CWE-184
View details
MEDIUM CVE-2025-14980

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated...

CVSS 6.5 CWE-200
View details
HIGH GHSA-mcmc-2m55-j8jj

vLLM introduced enhanced protection for CVE-2025-62164

CVSS 8.8 vllm Patch: 0.13.0 CWE-20
View details
HIGH GHSA-9726-w42j-3qjr

picklescan has Arbitrary file read using `io.FileIO`

picklescan Patch: 0.0.35 CWE-22
View details
MEDIUM CVE-2026-21894

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to...

CVSS 6.5 n8n CWE-290
View details
CRITICAL CVE-2026-21877

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full...

CVSS 9.9 n8n CWE-94
View details
CRITICAL CVE-2026-21858

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based...

CVSS 10.0 n8n
View details
MEDIUM CVE-2026-21851

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

CVSS 5.3 EPSS 0.0% monai Patch: 1.5.2 CWE-22
View details
MEDIUM CVE-2025-14371

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...

CVSS 4.3 CWE-862
View details
HIGH CVE-2026-0621

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded...

CVSS 7.5
View details
CRITICAL CVE-2026-21445

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue...

CVSS 9.1 EPSS 0.1% langflow CWE-306
View details
HIGH GHSA-46h3-79wf-xr6c

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter

picklescan Patch: 0.0.34 CWE-94
View details
HIGH GHSA-955r-x9j8-7rhh

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller

picklescan Patch: 0.0.34 CWE-94
View details
MEDIUM GHSA-6556-fwc2-fg2p

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-rrxm-2pvv-m66x

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef

picklescan Patch: 0.0.33 CWE-94
View details
MEDIUM GHSA-cffc-mxrf-mhh4

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-3329-ghmp-jmv5

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-x843-g5mx-g377

Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller

picklescan Patch: 0.0.33 CWE-94
View details
HIGH GHSA-r8g5-cgf2-4m4m

Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef

picklescan Patch: 0.0.33 CWE-502
View details
HIGH GHSA-hgrh-qx5j-jfwx

Picklescan Bypasses Unsafe Globals Check using pty.spawn

CVSS 8.8 picklescan Patch: 0.0.33 CWE-693
View details
HIGH GHSA-vqmv-47xg-9wpr

Picklescan missing detection when calling pty.spawn

picklescan Patch: 0.0.33 CWE-502
View details
HIGH GHSA-84r2-jw7c-4r5q

Picklescan has Incomplete List of Disallowed Inputs

picklescan Patch: 0.0.33 CWE-184
View details
HIGH GHSA-4675-36f9-wf6r

Picklescan does not block ctypes

picklescan Patch: 0.0.33 CWE-184
View details
HIGH GHSA-m273-6v24-x4m4

Picklescan vulnerable to Arbitrary File Writing

picklescan Patch: 0.0.33 CWE-502
View details
MEDIUM CVE-2025-68697

n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated...

CVSS 5.4 n8n CWE-269
View details
CRITICAL CVE-2025-68668

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with...

CVSS 9.9 n8n
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial