AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 220 results — Medium severity, has patchnbconvert: path traversal enables arbitrary file write
CVE-2026-39377 Langflow: cleartext auth storage exposes API keys
CVE-2026-6598 OpenClaw: path traversal in memory_get reads arbitrary workspace files
GHSA-f934-5rqf-xx47 Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
CVE-2026-35603 OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
GHSA-f7fh-qg34-x2xh OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure
GHSA-jhpv-5j76-m56h OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
GHSA-536q-mj95-h29h OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
GHSA-qmwg-qprg-3j38 OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
GHSA-527m-976r-jf79 OpenClaw: Browser tabs action select and close routes bypassed SSRF policy
GHSA-rj2p-j66c-mgqh OpenClaw: Nostr profile mutation routes allowed operator.write config persistence
GHSA-f3h5-h452-vp3j OpenClaw: screen_record outPath bypassed workspace-only filesystem guard
GHSA-jf25-7968-h2h5 OpenClaw: Browser SSRF policy default allowed private-network navigation
GHSA-53vx-pmqw-863c OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding
GHSA-xq94-r468-qwgj OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes
GHSA-2767-2q9v-9326 OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
GHSA-7wv4-cc7p-jhxc OpenClaw: Discord event cover images bypassed sandbox media normalization
GHSA-c9h3-5p7r-mrjh OpenClaw: Empty approver lists could grant explicit approval authorization
GHSA-49cg-279w-m73x OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
GHSA-7g8c-cfr3-vqqr OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms
GHSA-j6c7-3h5x-99g9 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert