AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 167 results — has patch
MEDIUM GHSA-x696-vm39-cp64

Picklescan has a missing detection when calling built-in python profile.Profile.run

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-g344-hcph-8vgg

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

picklescan Patch: 0.0.29
View details
MEDIUM GHSA-5qwp-399c-mjwf

Picklescan has a missing detection when calling built-in python trace.Trace.run

picklescan Patch: 0.0.29
View details
HIGH CVE-2025-5302

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

CVSS 8.6 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
HIGH CVE-2025-57809

XGrammar affected by Denial of Service by infinite recursion grammars

CVSS 7.5 EPSS 0.0% xgrammar Patch: 0.1.21 CWE-674
View details
MEDIUM GHSA-vv6j-3g6g-2pvj

Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-vr7h-p6mm-wpmh

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-h3qp-7fh3-f8h4

Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers

picklescan Patch: 0.0.28
View details
MEDIUM GHSA-f745-w6jp-hpxx

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-f4x7-rfwp-v3xw

Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-86cj-95qr-2p4f

Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get

picklescan Patch: 0.0.28 CWE-345
View details
MEDIUM GHSA-4r9r-ch6f-vxmx

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

picklescan Patch: 0.0.28 CWE-345
View details
HIGH CVE-2025-9141

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

CVSS 8.8 vllm Patch: 0.10.1.1 CWE-502
View details
HIGH GHSA-9gvj-pp9x-gcfr

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

picklescan Patch: 0.0.27 CWE-502
View details
CRITICAL CVE-2025-30404

ExecuTorch integer overflow vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-190
View details
CRITICAL CVE-2025-54950

ExecuTorch out-of-bounds access vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-125
View details
CRITICAL CVE-2025-54951

ExecuTorch vulnerable to Heap-based Buffer Overflow

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-122
View details
CRITICAL CVE-2025-54949

ExecuTorch heap buffer overflow vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-122
View details
CRITICAL CVE-2025-30405

ExecuTorch integer overflow vulnerability

CVSS 9.8 EPSS 0.2% executorch Patch: 0.7.0 CWE-190
View details
HIGH CVE-2025-30402

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

CVSS 8.1 EPSS 0.1% executorch Patch: 0.7.0-rc1 CWE-122
View details
MEDIUM CVE-2025-6211

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

CVSS 6.5 EPSS 0.1% llama-index Patch: 0.12.41 CWE-440
View details
HIGH CVE-2025-6209

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS 7.5 EPSS 0.1% llama-index-core Patch: 0.12.41 CWE-29
View details
MEDIUM CVE-2025-5472

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

CVSS 6.5 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
MEDIUM CVE-2025-3108

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

CVSS 5.0 EPSS 1.1% llama-index-core Patch: 0.12.41 CWE-1112
View details
MEDIUM CVE-2025-52967

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

CVSS 5.8 EPSS 0.1% mlflow Patch: 3.1.0 CWE-918
View details
CRITICAL CVE-2025-1793

llama_index vulnerable to SQL Injection

CVSS 9.8 EPSS 0.0% llama-index Patch: 0.12.28 CWE-89
View details
MEDIUM GHSA-j828-28rj-hfhp

vLLM vulnerable to Regular Expression Denial of Service

CVSS 4.3 vllm Patch: 0.9.0 CWE-1333
View details
HIGH CVE-2025-47783

label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

EPSS 0.2% label-studio Patch: 1.18.0 CWE-79
View details
HIGH CVE-2025-1752

LlamaIndex Vulnerable to Denial of Service (DoS)

CVSS 7.5 EPSS 0.2% llama-index Patch: 0.12.21 CWE-400
View details
CRITICAL CVE-2025-47241

Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL

CVSS 9.3 EPSS 0.2% browser-use Patch: 0.1.45 CWE-647
View details
HIGH CVE-2025-46567

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script...

CVSS 7.8 EPSS 0.2% llamafactory Patch: 0.9.3 CWE-502
View details
CRITICAL GHSA-ggpf-24jw-3fcw

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVSS 9.8 vllm Patch: 0.8.0 CWE-1395
View details
MEDIUM GHSA-hf3c-wxg2-49q9

vLLM vulnerable to Denial of Service by abusing xgrammar cache

CVSS 6.5 vllm Patch: 0.8.4 CWE-770
View details
MEDIUM CVE-2025-32381

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

CVSS 6.5 EPSS 0.3% xgrammar Patch: 0.1.18 CWE-770
View details
MEDIUM GHSA-v7x6-rv5q-mhwc

Picklescan missing detection when calling built-in python library function timeit.timeit()

picklescan Patch: 0.0.25 CWE-184
View details
MEDIUM GHSA-fj43-3qmq-673f

Picklescan failed to detect to some unsafe global function in Numpy library

picklescan Patch: 0.0.25 CWE-502
View details
HIGH CVE-2025-46417

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

EPSS 0.2% picklescan Patch: 0.0.25 CWE-184
View details
MEDIUM CVE-2025-0508

SageMaker Workflow component allows possibility of MD5 hash collisions

CVSS 5.9 EPSS 0.1% sagemaker Patch: 2.237.3 CWE-328
View details
HIGH CVE-2025-0628

LiteLLM Has an Improper Authorization Vulnerability

CVSS 8.1 EPSS 0.1% litellm Patch: 1.61.15 CWE-266
View details
HIGH CVE-2024-9606

LiteLLM Reveals Portion of API Key via a Logging File

CVSS 7.5 EPSS 0.1% litellm Patch: 1.44.12 CWE-117
View details
HIGH CVE-2024-8984

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

CVSS 7.5 EPSS 0.2% litellm Patch: 1.56.2 CWE-400
View details
HIGH CVE-2024-8060

Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions

CVSS 8.1 EPSS 0.9% open-webui Patch: 0.5.17 CWE-22
View details
HIGH CVE-2024-7776

Open Neural Network Exchange (ONNX) Path Traversal Vulnerability

CVSS 8.1 EPSS 1.5% onnx Patch: 1.17.0 CWE-22
View details
CRITICAL CVE-2024-8019

PyTorch Lightning path traversal vulnerability

CVSS 9.1 EPSS 1.1% pytorch-lightning Patch: 2.4.0 CWE-434
View details
HIGH GHSA-6wj5-5pgr-jwq8

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file

CVSS 7.5 open-webui Patch: 0.4.7 CWE-400
View details
HIGH CVE-2024-7806

Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability

CVSS 8.0 EPSS 0.7% open-webui Patch: 0.3.33 CWE-352
View details
HIGH CVE-2024-6982

LoLLMS Code Injection vulnerability

CVSS 8.4 EPSS 0.1% lollms Patch: 11.0.0 CWE-94
View details
MEDIUM CVE-2024-12910

LlamaIndex Uncontrolled Resource Consumption vulnerability

CVSS 5.9 EPSS 0.3% llama-index Patch: 0.12.9 CWE-400
View details
MEDIUM CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from...

CVSS 5.3 EPSS 0.1% langchain-core Patch: 0.1.53 CWE-497
View details
HIGH CVE-2024-10188

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function...

CVSS 7.5 EPSS 0.1% litellm Patch: 1.53.1.dev1 CWE-400
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial