AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 377 results — Medium severity
MEDIUM CVE-2025-3933

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-6716

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored...

CVSS 6.4
View details
MEDIUM CVE-2025-7021

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login...

CVSS 6.5 operator
View details
MEDIUM CVE-2025-6211

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

CVSS 6.5 EPSS 0.1% llama-index Patch: 0.12.41 CWE-440
View details
MEDIUM CVE-2025-6210

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

CVSS 6.2 EPSS 0.0% CWE-22
View details
MEDIUM CVE-2025-5472

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

CVSS 6.5 EPSS 0.1% llama-index-core Patch: 0.12.38 CWE-674
View details
MEDIUM CVE-2025-3044

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

CVSS 5.3 EPSS 0.1% CWE-440
View details
MEDIUM CVE-2025-3264

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`....

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-3263

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the...

CVSS 5.3 EPSS 0.0% transformers CWE-1333
View details
MEDIUM CVE-2025-3108

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

CVSS 5.0 EPSS 1.1% llama-index-core Patch: 0.12.41 CWE-1112
View details
MEDIUM CVE-2025-52554

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow...

CVSS 4.3 n8n
View details
MEDIUM CVE-2025-45809

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

CVSS 5.4 litellm
View details
MEDIUM CVE-2025-49595

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or...

CVSS 4.9 n8n
View details
MEDIUM CVE-2025-6854

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The...

CVSS 4.3 EPSS 0.1% langchain-chatchat CWE-22
View details
MEDIUM CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-52967

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

CVSS 5.8 EPSS 0.1% mlflow Patch: 3.1.0 CWE-918
View details
MEDIUM CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to...

CVSS 6.5 EPSS 0.1% vllm CWE-20
View details
MEDIUM CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48887

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file...

CVSS 6.5 EPSS 0.1% vllm CWE-1333
View details
MEDIUM GHSA-j828-28rj-hfhp

vLLM vulnerable to Regular Expression Denial of Service

CVSS 4.3 vllm Patch: 0.9.0 CWE-1333
View details
MEDIUM CVE-2025-1194

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the...

CVSS 6.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-46343

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary...

CVSS 5.4 n8n
View details
MEDIUM CVE-2025-3730

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation...

CVSS 5.5 EPSS 0.1% pytorch CWE-404
View details
MEDIUM GHSA-hf3c-wxg2-49q9

vLLM vulnerable to Denial of Service by abusing xgrammar cache

CVSS 6.5 vllm Patch: 0.8.4 CWE-770
View details
MEDIUM CVE-2025-32381

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

CVSS 6.5 EPSS 0.3% xgrammar Patch: 0.1.18 CWE-770
View details
MEDIUM GHSA-v7x6-rv5q-mhwc

Picklescan missing detection when calling built-in python library function timeit.timeit()

picklescan Patch: 0.0.25 CWE-184
View details
MEDIUM GHSA-fj43-3qmq-673f

Picklescan failed to detect to some unsafe global function in Numpy library

picklescan Patch: 0.0.25 CWE-502
View details
MEDIUM CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is...

CVSS 5.5 pytorch
View details
MEDIUM CVE-2025-31843

Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for...

CVSS 4.3
View details
MEDIUM CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption....

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2953

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of...

CVSS 5.5 EPSS 0.2% pytorch CWE-404
View details
MEDIUM CVE-2025-0508

SageMaker Workflow component allows possibility of MD5 hash collisions

CVSS 5.9 EPSS 0.1% sagemaker Patch: 2.237.3 CWE-328
View details
MEDIUM CVE-2024-7045

Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read

CVSS 4.3 EPSS 0.1% open-webui CWE-862
View details
MEDIUM CVE-2024-7035

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)

CVSS 6.9 EPSS 0.0% open-webui CWE-352
View details
MEDIUM CVE-2024-7046

Open WebUI Allows Viewing of Admin Details

CVSS 4.3 EPSS 0.1% open-webui CWE-475
View details
MEDIUM CVE-2024-7034

Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint

CVSS 6.5 EPSS 3.0% open-webui CWE-22
View details
MEDIUM CVE-2024-7033

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS 6.5 EPSS 1.2% open-webui CWE-29
View details
MEDIUM CVE-2024-7044

Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload

CVSS 6.8 EPSS 0.3% open-webui CWE-79
View details
MEDIUM CVE-2024-12910

LlamaIndex Uncontrolled Resource Consumption vulnerability

CVSS 5.9 EPSS 0.3% llama-index Patch: 0.12.9 CWE-400
View details
MEDIUM GHSA-564p-rx2q-4c8v

BentoML Open Redirect vulnerability

CVSS 6.1 bentoml CWE-601
View details
MEDIUM CVE-2025-1474

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be...

CVSS 5.5 EPSS 0.1% mlflow CWE-521
View details
MEDIUM CVE-2024-8021

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited...

CVSS 6.1 EPSS 2.7% gradio CWE-601
View details
MEDIUM CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment...

CVSS 5.3 EPSS 0.1% mlflow CWE-400
View details
MEDIUM CVE-2024-6577

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This...

CVSS 6.3 EPSS 0.1%
View details
MEDIUM CVE-2024-12217

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow...

CVSS 5.3 EPSS 0.1% gradio CWE-22
View details
MEDIUM CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from...

CVSS 5.3 EPSS 0.1% langchain-core Patch: 0.1.53 CWE-497
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial