AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

76

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 220 results — Medium severity, has patch
MEDIUM EXPLOIT AVAIL

praisonaiagents: glob traversal leaks filesystem metadata

CVE-2026-40152
5.3
EPSS 0.0%
Data Extraction Privacy Violation Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-22 11 5 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: unauthenticated agent config and system prompt disclosure

CVE-2026-40151
5.3
EPSS 0.0%
Data Extraction Auth Bypass Agent API
PraisonAI Patch: 4.5.128 CWE-200 1 6 ATLAS
MEDIUM EXPLOIT AVAIL

PraisonAI: unbounded body read enables local DoS

CVE-2026-40115
6.2
EPSS 0.1%
DoS Auth Bypass Agent Framework
PraisonAI Patch: 4.5.128 CWE-770 1 3 ATLAS
MEDIUM EXPLOIT AVAIL

OpenClaw: SSRF via web-fetch enables internal network pivot

CVE-2026-6011
5.6
EPSS 0.1%
Data Extraction Privacy Violation Agent Plugin
openclaw Patch: 2026.1.29 CWE-918 4 4 ATLAS 1 incident
MEDIUM EXPLOIT AVAIL

PraisonAI: arbitrary file read via unguarded skill tool

CVE-2026-40117
6.2
EPSS 0.0%
Prompt Injection Data Extraction Data Leakage Agent Plugin
praisonaiagents Patch: 1.5.128 CWE-862 11 5 ATLAS
MEDIUM

openclaw: base64 pre-alloc bypass causes resource exhaustion

GHSA-ccx3-fw7q-rr2r
--
DoS Supply Chain Agent Plugin
openclaw Patch: 2026.4.8 CWE-770 4 4 ATLAS 1 incident
MEDIUM

openclaw: no integrity check on ClawHub plugin installs

GHSA-3vvq-q2qc-7rmp
--
Supply Chain Code Execution Agent Plugin
openclaw Patch: 2026.4.8 CWE-353 4 4 ATLAS 1 incident
MEDIUM

openclaw: env var injection enables host exec hijacking

GHSA-w9j9-w4cp-6wgr
--
Code Execution Supply Chain Agent Plugin
openclaw Patch: 2026.4.8 CWE-78 4 6 ATLAS 1 incident
MEDIUM

OpenClaw: SSRF bypass via Playwright redirect handling

GHSA-w8g9-x8gx-crmm
--
Supply Chain Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.8 CWE-918 4 7 ATLAS 1 incident
MEDIUM

OpenClaw: SSRF bypass via interaction-triggered navigation

GHSA-vr5g-mmx7-h897
--
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.4.8 CWE-918 4 7 ATLAS 1 incident
MEDIUM

OpenClaw: scope misconfiguration enables unauthorized node pairing

GHSA-67mf-f936-ppxf
--
Auth Bypass Supply Chain Agent Plugin
openclaw Patch: 2026.4.8 CWE-269 4 5 ATLAS 1 incident
MEDIUM

openclaw: SSRF bypass in QQ Bot media fetch paths

GHSA-3fv3-6p2v-gxwj
--
Data Extraction Auth Bypass Agent Plugin
openclaw Patch: 2026.4.8 CWE-918 4 5 ATLAS 1 incident
MEDIUM

openclaw: WS sessions persist after gateway token rotation

GHSA-5h3f-885m-v22w
--
Auth Bypass Agent
openclaw Patch: 2026.4.8 CWE-613 4 3 ATLAS 1 incident
MEDIUM

OpenClaw: cross-channel allowlist write bypass

GHSA-vc32-h5mq-453v
--
Auth Bypass Agent
openclaw Patch: 2026.4.8 4 3 ATLAS 1 incident
MEDIUM

OpenClaw: stale auth closure bypasses gateway access control

GHSA-68x5-xx89-w9mm
--
Auth Bypass Agent
openclaw Patch: 2026.4.8 CWE-613 4 3 ATLAS 1 incident
MEDIUM

OpenClaw: auth bypass enables persistent browser profile mutation

GHSA-cmfr-9m2r-xwhq
--
Auth Bypass Agent Plugin
openclaw Patch: 2026.4.8 CWE-863 4 4 ATLAS 1 incident
MEDIUM

OpenClaw: token rotation bypasses role approval

GHSA-whf9-3hcx-gq54
--
Auth Bypass Agent
openclaw Patch: 2026.4.8 CWE-863 4 4 ATLAS 1 incident
MEDIUM

openclaw: local file exfiltration via trusted MEDIA refs

GHSA-qqq7-4hxc-x63c
--
Data Extraction Privacy Violation Agent Plugin
openclaw Patch: 2026.4.8 CWE-668 4 4 ATLAS 1 incident
MEDIUM

OpenClaw: eval approval bypass enables unintended code exec

GHSA-q2gc-xjqw-qp89
--
Auth Bypass Code Execution Agent Framework
openclaw Patch: 2026.4.8 CWE-20 4 5 ATLAS 1 incident
MEDIUM

LangChain: f-string template injection exposes object internals

GHSA-926x-3r5x-gfhw
5.3
Data Extraction Prompt Injection Framework
langchain-core Patch: 0.3.84 CWE-20 4.4K 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial