AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severityOpenClaw: Heartbeat owner downgrade missed local async exec completion events
GHSA-g375-h3v6-4873 OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
GHSA-g2hm-779g-vm32 OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
GHSA-c4qm-58hj-j6pj OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
GHSA-jwrq-8g5x-5fhm OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
GHSA-92jp-89mq-4374 langchain-text-splitters: SSRF bypass exposes cloud metadata
GHSA-fv5p-p927-qmxr Flowise: SSRF bypass enables cloud metadata access
GHSA-9hrv-gvrv-6gf2 Flowise: SSRF bypass enables cloud credential theft
GHSA-qqvm-66q4-vf5c Flowise: path traversal allows arbitrary file write via vector store
GHSA-w6v6-49gh-mc9w Flowise: hardcoded default key enables JWT token forgery
GHSA-m7mq-85xj-9x33 Flowise: hardcoded session secret enables auth bypass
GHSA-2qqc-p94c-hxwh Flowise: hardcoded JWT defaults enable full auth bypass
GHSA-cc4f-hjpj-g9p8 Flowise: unauthenticated SSO config exposes OAuth secrets
GHSA-6pcv-j4jx-m4vx langsmith: prototype pollution enables auth bypass, RCE
CVE-2026-40190 rembg: path traversal exposes arbitrary files via HTTP API
CVE-2026-40086 PraisonAI: SQL injection via table_prefix exposes DB
GHSA-x783-xp3g-mqhp PraisonAI: tool approval bypass leaks env credentials
GHSA-ffp3-3562-8cv3 PraisonAI: MCP env inheritance exposes API keys
CVE-2026-40159 PraisonAI: decompression bomb causes disk exhaustion
CVE-2026-40148 praisonaiagents: glob traversal leaks filesystem metadata
CVE-2026-40152 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert