AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1625 resultsopen-webui: auth bypass allows unrestricted model access
CVE-2026-44556 open-webui: access control bypass via model chaining
CVE-2026-44555 open-webui: Redis cache poisoning enables cross-instance tool hijack
CVE-2026-44552 open-webui: stale Socket.IO role allows cross-user note R/W
CVE-2026-44553 open-webui: mass assignment enables cross-user folder injection
CVE-2026-44550 open-webui: LDAP auth bypass — full account takeover
CVE-2026-44551 open-webui: XSS in model descriptions steals session tokens
CVE-2026-44721 n8n-mcp: path traversal + SSRF exposes n8n API keys
GHSA-8g7g-hmwm-6rv2 n8n-MCP: SSRF allows internal network access via webhook tools
CVE-2026-44694 LiteLLM: RCE via MCP test endpoint command injection
CVE-2026-42271 LiteLLM: SQL injection exposes LLM API credentials
CVE-2026-42208 LiteLLM: SSTI in prompt template endpoint enables RCE
CVE-2026-42203 BentoML: symlink traversal exfiltrates host secrets at build
CVE-2026-40610 diffusers: trust_remote_code bypass enables silent RCE
CVE-2026-44513 vm2: sandbox escape via nesting:true enables RCE
CVE-2026-44007 diffusers: silent RCE via None.py trust_remote_code bypass
GHSA-j7w6-vpvq-j3gm Aegra: cross-tenant IDOR hijacks user thread data
CVE-2026-44504 pytorch-lightning: supply chain, credential harvesting
CVE-2026-44484 vercel: auth token leak in AI agent non-interactive mode
CVE-2026-44479 @axonflow/openclaw: credential exposure via insecure file permissions
GHSA-cqmh-pcgr-q42f Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert