AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 512 results — has patchopenclaw: SSRF policy bypass in CDP browser profile creation
GHSA-j4c5-89f5-f3pm OpenClaw: auth bypass enables cross-device session hijack
GHSA-xrq9-jm7v-g9h7 openclaw: SSRF in QQBot media upload bypasses validation
GHSA-c4qg-j8jg-42q5 openclaw: env var injection via MCP stdio config
GHSA-mj59-h3q9-ghfh openclaw: trust-label bypass amplifies prompt injection
GHSA-57r2-h2wj-g887 openclaw: env namespace injection steers agent runtime
GHSA-hxvm-xjvf-93f3 openclaw: DM policy bypass via Feishu card-action callbacks
GHSA-72q8-jcmc-97wx OpenClaw: auth scope bypass exposes assistant-media files
GHSA-v8qf-fr4g-28p2 openclaw: session key auth bypass in webhook routing
GHSA-2xcp-x87w-q377 n8n-mcp: credential exposure via HTTP transport logging
GHSA-wg4g-395p-mqv3 litellm: RCE via MCP test endpoints privilege bypass
GHSA-v4p8-mg3p-g94g Claude Code: git worktree trust bypass executes hooks
CVE-2026-40068 litellm: SQLi exposes all managed LLM API credentials
GHSA-r75f-5x8p-qvmc Ray: Parquet RCE via Arrow extension deserialization
CVE-2026-41486 LiteLLM: RCE via unsandboxed prompt template rendering
GHSA-xqmj-j6mv-4862 n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
CVE-2026-41495 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41264 nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
CVE-2026-39378 nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
CVE-2026-39377 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to...
CVE-2026-39861 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert