AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 512 results — has patch
HIGH

OpenClaw: RCE via malicious repo setup-api.js

GHSA-r39h-4c2p-3jxp
7.8
Supply Chain Code Execution Agent Plugin
openclaw Patch: 2026.4.23 CWE-94 4 4 ATLAS 1 incident
MEDIUM

openclaw: stale webhook secret survives credential rotation

GHSA-q8ff-7ffm-m3r9
6.0
Auth Bypass Agent Plugin
openclaw Patch: 2026.4.23 CWE-613 4 3 ATLAS 1 incident
CRITICAL

Langflow: path traversal allows arbitrary directory deletion

CVE-2026-42048
9.6
DoS Auth Bypass Framework RAG
langflow Patch: 1.9.0 CWE-22 3 ATLAS
MEDIUM

JupyterHub: CSRF bypass on spawn and share endpoints

CVE-2026-40864
5.4
Auth Bypass DoS Framework
jupyterhub Patch: 5.4.5 CWE-352 1.9K 4 ATLAS
MEDIUM

jupyter-server: auth cookie survives password reset

CVE-2026-40934
6.8
EPSS 0.1%
Auth Bypass Data Extraction Framework API
jupyter-server Patch: 2.18.0 CWE-613 1.9K 4 ATLAS
HIGH

Jupyter Server: CORS bypass via regex anchor omission

CVE-2026-40110
--
EPSS 0.0%
Auth Bypass Code Execution Data Extraction Framework API
jupyter-server Patch: 2.18.0 CWE-777 1.9K 4 ATLAS
HIGH

Jupyter Server: path traversal leaks sibling directories

CVE-2026-35397
7.1
EPSS 0.0%
Data Extraction Privacy Violation Framework
jupyter-server Patch: 2.18.0 CWE-22 1.9K 4 ATLAS
MEDIUM

jupyter-server: Open redirect enables credential phishing

CVE-2025-61669
--
EPSS 0.0%
Social Engineering Auth Bypass Framework API
jupyter-server Patch: 2.18.0 CWE-601 1.9K 5 ATLAS
MEDIUM

OpenClaw: symlink traversal exposes host filesystem

CVE-2026-43570
6.5
EPSS 0.1%
Supply Chain Data Extraction Agent Plugin
openclaw Patch: 2026.4.5 CWE-61 4 4 ATLAS 1 incident
MEDIUM

openclaw: auth bypass exposes Gateway bootstrap config

GHSA-93rg-2xm5-2p9v
--
Auth Bypass Data Leakage Agent API
openclaw Patch: 2026.4.22 CWE-287 4 4 ATLAS 1 incident
MEDIUM

openclaw: TOCTOU race allows out-of-sandbox file read

GHSA-5h3g-6xhh-rg6p
--
Data Extraction Privacy Violation Agent Plugin
openclaw Patch: 2026.4.22 CWE-367 4 4 ATLAS 1 incident
HIGH

openclaw: TOCTOU sandbox escape via symlink swap

GHSA-wppj-c6mr-83jj
--
Code Execution Supply Chain Auth Bypass Agent Plugin
openclaw Patch: 2026.4.22 CWE-367 4 4 ATLAS 1 incident
MEDIUM

OpenClaw: exec allowlist bypass allows hidden shell code

GHSA-x3h8-jrgh-p8jx
--
Code Execution Auth Bypass Agent Plugin
openclaw Patch: 2026.4.22 CWE-200 4 4 ATLAS 1 incident
HIGH

openclaw: MCP owner-context spoofing, privilege escalation

GHSA-r6xh-pqhr-v4xh
--
Auth Bypass Code Execution Agent Framework
openclaw Patch: 2026.4.22 CWE-284 4 4 ATLAS 1 incident
MEDIUM

OpenClaw: .env injection redirects connector endpoints

GHSA-55cf-xx38-4p9p
--
Supply Chain Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.22 CWE-427 4 4 ATLAS 1 incident
MEDIUM

openclaw: ACP child session security envelope bypass

GHSA-q3jj-46pq-826r
--
Auth Bypass Code Execution Agent Framework
openclaw Patch: 2026.4.22 CWE-277 4 4 ATLAS 1 incident
MEDIUM

openclaw: SSRF bypass via Zalo plugin photo URLs

GHSA-2hh7-c75g-qj2r
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.22 CWE-918 4 3 ATLAS 1 incident
MEDIUM

OpenClaw: sender allowlist bypass via Slack thread context

CVE-2026-41358
5.4
EPSS 0.0%
Auth Bypass Prompt Injection Data Leakage Agent Plugin
openclaw Patch: 2026.4.2 CWE-346 4 4 ATLAS 1 incident
HIGH

n8n-mcp: SSRF bypass via IPv6 leaks API keys

CVE-2026-42449
8.5
EPSS 0.0%
Data Extraction Auth Bypass Supply Chain Agent Plugin
n8n-mcp Patch: 2.47.14 CWE-918 16 5 ATLAS
HIGH

Jupyter Notebook: stored XSS enables full account takeover

CVE-2026-40171
--
EPSS 0.1%
Auth Bypass Code Execution Data Extraction Framework Training Data
@jupyterlab/help-extension Patch: 4.5.7 CWE-79 1.9K 7 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial