AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1625 resultspraisonai: RCE via unpatched tool_override exec_module
CVE-2026-44334 praisonaiagents: SSRF via URL parser confusion bypass
CVE-2026-44335 GitPython: git config injection enables hook RCE
CVE-2026-44244 vLLM: speculative decoding DoS via penalty params
CVE-2026-44223 JupyterLab: one-click RCE via notebook HTML cell output
CVE-2026-42557 mistune: ReDoS exposes Jupyter/AI services to DoS
CVE-2026-33079 vLLM: token injection DoS via multimodal placeholders
CVE-2026-44222 ciguard: symlink traversal exposes secrets via MCP agent
CVE-2026-44220 JupyterLab: Extension allow-list bypass enables privesc
CVE-2026-42266 wireshark-mcp: path traversal enables arbitrary file write via MCP
CVE-2026-43901 PPTAgent: eval injection enables RCE via LLM prompt injection
CVE-2026-42079 openclaw: Model bypasses authz to persist unsafe config
GHSA-cwj3-vqpp-pmxr OpenClaw: RCE via malicious repo setup-api.js
GHSA-r39h-4c2p-3jxp openclaw: stale webhook secret survives credential rotation
GHSA-q8ff-7ffm-m3r9 Langflow: path traversal allows arbitrary directory deletion
CVE-2026-42048 JupyterHub: CSRF bypass on spawn and share endpoints
CVE-2026-40864 LobeChat: XSS-to-RCE via exposed Electron IPC
CVE-2026-42045 Langchain-Chatchat: predictable file IDs leak uploaded files
CVE-2026-7847 jupyter-server: auth cookie survives password reset
CVE-2026-40934 Jupyter Server: CORS bypass via regex anchor omission
CVE-2026-40110 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert