AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

76

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 167 results — Critical severity, no patch
CRITICAL EXPLOIT AVAIL

n8n-workflows: path traversal in download_workflow endpoint

CVE-2025-55526
9.1
EPSS 0.6%
Data Extraction Auth Bypass Code Execution Agent Framework API
fastapi 16 5 ATLAS
CRITICAL EXPLOIT AVAIL

Azure OpenAI: SSRF EoP, no auth required (CVSS 10)

CVE-2025-53767
10.0
EPSS 0.5%
Auth Bypass Data Extraction Privacy Violation API Inference
azure_openai 13.8K 6 ATLAS
CRITICAL EXPLOIT AVAIL

ChatGLM-Webui: arbitrary file read, no auth required

CVE-2025-45150
9.8
EPSS 0.1%
Data Extraction Auth Bypass Framework API
langchain-chatglm-webui 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: unauthenticated SSRF via file upload URLs

CVE-2025-54381
9.9
EPSS 0.7%
Supply Chain Data Extraction Auth Bypass Framework Inference API
bentoml CWE-918 23 5 ATLAS
CRITICAL EXPLOIT AVAIL

LangChain GmailToolkit: indirect prompt injection to RCE

CVE-2025-46059
9.8
EPSS 0.3%
Prompt Injection Code Execution Data Extraction Framework Agent Plugin
6 ATLAS
CRITICAL EXPLOIT AVAIL

smolagents: sandbox escape enables unauthenticated RCE

CVE-2025-5120
10.0
EPSS 0.4%
Code Execution Supply Chain Data Leakage Framework Agent
smolagents CWE-94 88 5 ATLAS
CRITICAL EXPLOIT AVAIL

Langchain-Chatchat: path traversal in KB upload

CVE-2025-6853
9.8
EPSS 0.6%
Code Execution Data Extraction Supply Chain Framework RAG
langchain-chatchat CWE-22 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

LLaMA-Factory: RCE via unsafe checkpoint deserialization

CVE-2025-53002
9.8
EPSS 4.2%
Code Execution Supply Chain Framework Model
llamafactory CWE-94 1 6 ATLAS
CRITICAL EXPLOIT AVAIL

LangChain RequestsToolkit: SSRF exposes cloud metadata

CVE-2025-2828
10.0
EPSS 0.2%
Data Extraction Auth Bypass Framework Agent
langchain CWE-918 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

vLLM: RCE via exposed TCPStore in distributed inference

CVE-2025-47277
9.8
EPSS 0.9%
Code Execution Data Extraction Inference Framework
vllm CWE-502 127 4 ATLAS
CRITICAL EXPLOIT AVAIL

vLLM: RCE via pickle deserialization on ZeroMQ

CVE-2025-32444
9.8
EPSS 2.5%
Code Execution Supply Chain Inference Framework
vllm CWE-502 127 5 ATLAS
CRITICAL EXPLOIT AVAIL

PyTorch: RCE bypasses weights_only=True safe-load guard

CVE-2025-32434
9.8
EPSS 1.2%
Code Execution Supply Chain Framework Model Inference
pytorch CWE-502 21.9K 6 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: RCE via insecure deserialization in runner

CVE-2025-32375
9.8
EPSS 67.3%
Code Execution Data Extraction Supply Chain Framework Inference
bentoml CWE-502 23 5 ATLAS
CRITICAL KEV SCANNER

Langflow: Unauth RCE via code injection endpoint

CVE-2025-3248
9.8
EPSS 91.8%
Code Execution Auth Bypass Framework Agent
langflow CWE-94 5 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: unauthenticated RCE via insecure deserialization

CVE-2025-27520
9.8
EPSS 81.0%
Code Execution Supply Chain Framework Inference
bentoml CWE-502 23 5 ATLAS
CRITICAL EXPLOIT AVAIL

InvokeAI: RCE via unsafe torch.load deserialization

CVE-2024-12029
9.8
EPSS 44.2%
Code Execution Supply Chain Framework Model
CWE-502 5 ATLAS
CRITICAL

vLLM: RCE via pickle deserialization in distributed API

CVE-2024-9052
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Inference
vllm CWE-502 127 3 ATLAS
CRITICAL EXPLOIT AVAIL

llama-index finchat: SQL injection enables RCE

CVE-2024-12909
10.0
EPSS 4.1%
Code Execution Supply Chain Data Extraction Agent Framework Plugin
llama-index-packs-finchat CWE-89 229 5 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: unauthenticated RCE via runner deserialization

CVE-2024-9070
9.8
EPSS 0.4%
Code Execution Supply Chain Framework Inference
bentoml CWE-502 23 3 ATLAS
CRITICAL EXPLOIT AVAIL

vllm: RCE via unsafe pickle deserialization in RPC server

CVE-2024-9053
9.8
EPSS 10.0%
Code Execution Supply Chain Framework Inference
vllm CWE-78 127 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial