AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 684 results — High severityFlowise: mass assignment enables cross-workspace IDOR
CVE-2026-41277 Flowise: HTTP password reset link allows MITM takeover
CVE-2026-41275 Flowise: auth bypass exposes OAuth 2.0 tokens
CVE-2026-41273 Flowise: SSRF bypass via DNS rebinding exposes internal networks
CVE-2026-41272 Flowise: SSRF via prompt template injection in API Chain
CVE-2026-41271 Flowise: SSRF bypass exposes cloud metadata services
CVE-2026-41270 Flowise: unrestricted file upload enables persistent RCE
CVE-2026-41269 Flowise: unauthenticated API key exposure via chatbot config
CVE-2026-41266 Flowise: RCE via unsanitized input in AirtableAgent
CVE-2026-41138 Flowise: RCE via CSVAgent unsanitized code injection
CVE-2026-41137 engramx: CSRF injects persistent prompts into AI agents
GHSA-2r2p-4cgf-hv7h InstructLab: RCE via hardcoded trust_remote_code flag
CVE-2026-6859 Claude Code: sandbox escape via symlink allows arbitrary write
CVE-2026-39861 Langflow: unauthenticated file upload allows RCE
CVE-2026-6596 openclaw: path traversal leaks files and NTLM credentials
GHSA-mr34-9552-qr95 OpenClaw: auth bypass lets DM senders run room commands
GHSA-2gvc-4f3c-2855 OpenClaw: stale bearer token survives SecretRef rotation
GHSA-xmxx-7p24-h892 PraisonAI: SQL injection across 9 DB backends
GHSA-rg3h-x3jw-7jm5 openclaw: path traversal exposes host files via media tags
GHSA-66r7-m7xm-v49h openclaw: exec approval bypass via opaque multi-call binaries
GHSA-2cq5-mf3v-mx44 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert