AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 167 results — Critical severity, no patchn8n-workflows: path traversal in download_workflow endpoint
CVE-2025-55526 Azure OpenAI: SSRF EoP, no auth required (CVSS 10)
CVE-2025-53767 ChatGLM-Webui: arbitrary file read, no auth required
CVE-2025-45150 BentoML: unauthenticated SSRF via file upload URLs
CVE-2025-54381 LangChain GmailToolkit: indirect prompt injection to RCE
CVE-2025-46059 smolagents: sandbox escape enables unauthenticated RCE
CVE-2025-5120 Langchain-Chatchat: path traversal in KB upload
CVE-2025-6853 LLaMA-Factory: RCE via unsafe checkpoint deserialization
CVE-2025-53002 LangChain RequestsToolkit: SSRF exposes cloud metadata
CVE-2025-2828 vLLM: RCE via exposed TCPStore in distributed inference
CVE-2025-47277 vLLM: RCE via pickle deserialization on ZeroMQ
CVE-2025-32444 PyTorch: RCE bypasses weights_only=True safe-load guard
CVE-2025-32434 BentoML: RCE via insecure deserialization in runner
CVE-2025-32375 Langflow: Unauth RCE via code injection endpoint
CVE-2025-3248 BentoML: unauthenticated RCE via insecure deserialization
CVE-2025-27520 InvokeAI: RCE via unsafe torch.load deserialization
CVE-2024-12029 vLLM: RCE via pickle deserialization in distributed API
CVE-2024-9052 llama-index finchat: SQL injection enables RCE
CVE-2024-12909 BentoML: unauthenticated RCE via runner deserialization
CVE-2024-9070 vllm: RCE via unsafe pickle deserialization in RPC server
CVE-2024-9053 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert