AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 1604 resultsLlamaIndex Obsidian: symlink traversal exposes host files
CVE-2025-3046 llama-index ArxivReader: MD5 collision corrupts training data
CVE-2025-3044 llama-index Papers Loader: XML expansion DoS
CVE-2025-3225 Transformers: URL validation bypass exposes image pipeline
CVE-2025-3777 Transformers: ReDoS in dynamic module loader causes DoS
CVE-2025-3264 Transformers: ReDoS in config loader causes serving DoS
CVE-2025-3263 Transformers: ReDoS in chat.py causes CPU exhaustion
CVE-2025-3262 llama-index: RCE via unsafe pickle deserialization
CVE-2025-3108 n8n: broken authz enables cross-user workflow termination
CVE-2025-52554 LiteLLM: SQL injection in key management API
CVE-2025-45809 n8n: DoS via empty filesystem URI in binary-data API
CVE-2025-49595 Slack MCP: zero-click exfiltration via link unfurling
CVE-2025-34072 Langchain-Chatchat: path traversal exposes system files
CVE-2025-6855 Langchain-Chatchat: path traversal in file API exposes host FS
CVE-2025-6854 Langchain-Chatchat: path traversal in KB upload
CVE-2025-6853 n8n: open redirect enables phishing via login flow
CVE-2025-49592 LLaMA-Factory: RCE via unsafe checkpoint deserialization
CVE-2025-53002 LangChain RequestsToolkit: SSRF exposes cloud metadata
CVE-2025-2828 MLflow: unauthenticated SSRF in gateway proxy
CVE-2025-52967 Hive Support WP: OpenAI key theft + prompt hijack
CVE-2025-5018 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert