AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

230

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
HIGH

Langflow: IDOR exposes cross-tenant flow data and deletion

CVE-2026-6542
8.1
EPSS 0.0%
Data Extraction Privacy Violation Auth Bypass Framework Agent
langflow CWE-639 5 ATLAS
MEDIUM

Langflow: path traversal allows arbitrary file read

CVE-2026-3345
6.5
EPSS 0.1%
Data Extraction Data Leakage Framework Agent
langflow CWE-22 3 ATLAS
HIGH

Langflow Desktop: IDOR leaks user images unauthenticated

CVE-2026-4503
7.5
EPSS 0.1%
Privacy Violation Data Extraction Auth Bypass Framework Agent
langflow CWE-639 3 ATLAS
MEDIUM

Langflow: path traversal enables arbitrary file write

CVE-2026-4502
6.5
EPSS 0.1%
Code Execution Supply Chain Framework Agent
langflow CWE-22 4 ATLAS
MEDIUM

Langflow Desktop: stored XSS enables credential theft

CVE-2026-3346
6.4
EPSS 0.0%
Data Extraction Auth Bypass Framework
langflow CWE-89 4 ATLAS
MEDIUM

IBM Langflow: SSRF enables internal network enumeration

CVE-2026-3340
6.5
EPSS 0.0%
Data Extraction Privacy Violation Framework Agent
langflow CWE-918 4 ATLAS
HIGH

n8n-mcp: SSRF bypass via IPv6 leaks API keys

CVE-2026-42449
8.5
EPSS 0.0%
Data Extraction Auth Bypass Supply Chain Agent Plugin
n8n-mcp Patch: 2.47.14 CWE-918 16 5 ATLAS
HIGH

Jupyter Notebook: stored XSS enables full account takeover

CVE-2026-40171
--
EPSS 0.1%
Auth Bypass Code Execution Data Extraction Framework Training Data
@jupyterlab/help-extension Patch: 4.5.7 CWE-79 1.9K 7 ATLAS
AWAITING NVD

@anthropic-ai/sdk: insecure file perms expose agent memory

CVE-2026-41686
--
EPSS 0.0%
Data Leakage Privacy Violation Prompt Injection Agent API Framework
@anthropic-ai/sdk Patch: 0.91.1 CWE-732 240 5 ATLAS
HIGH EXPLOIT AVAIL

marked: infinite recursion DoS crashes Node.js via OOM

CVE-2026-41680
7.5
EPSS 0.1%
DoS Framework
marked Patch: 18.0.2 CWE-400 3.8K 4 ATLAS
MEDIUM

openclaw: path traversal exposes host files via audio embed

GHSA-gfg9-5357-hv4c
--
Prompt Injection Data Extraction Agent Plugin
openclaw Patch: 2026.4.15 CWE-22 4 5 ATLAS 1 incident
MEDIUM

openclaw: auth bypass in owner command enforcement

GHSA-c28g-vh7m-fm7v
--
Auth Bypass Agent Plugin
openclaw Patch: 2026.4.21 CWE-862 4 5 ATLAS 1 incident
AWAITING NVD

n8n: XML Node prototype pollution → RCE

CVE-2026-42232
--
EPSS 0.1%
Code Execution Data Extraction Agent Plugin Framework
n8n Patch: 2.18.1 CWE-1321 16 5 ATLAS
AWAITING NVD

n8n: prototype pollution → RCE via Git node SSH

CVE-2026-42231
--
EPSS 0.3%
Code Execution Supply Chain Agent Plugin
n8n Patch: 1.123.32 CWE-1321 16 6 ATLAS
AWAITING NVD

n8n: stored XSS via MCP OAuth steals agent sessions

CVE-2026-42235
--
EPSS 0.1%
Code Execution Data Extraction Auth Bypass Agent Plugin Framework
n8n Patch: 1.123.32 CWE-87 16 7 ATLAS
AWAITING NVD

n8n: IDOR exposes cross-user API key exfiltration

CVE-2026-42226
--
EPSS 0.1%
Auth Bypass Data Extraction Privacy Violation Agent API Framework
n8n Patch: 2.17.5 CWE-862 16 6 ATLAS
AWAITING NVD

n8n: Python sandbox escape enables container RCE

CVE-2026-42234
--
EPSS 0.1%
Code Execution Supply Chain Data Extraction Agent Framework Plugin
n8n Patch: 1.123.32 CWE-94 16 5 ATLAS
AWAITING NVD

n8n: IDOR leaks cross-project variables via API key

CVE-2026-42227
--
EPSS 0.0%
Auth Bypass Data Extraction Agent API
n8n Patch: 1.123.32 CWE-639 16 4 ATLAS
AWAITING NVD

n8n: unauthenticated MCP endpoint causes memory DoS

CVE-2026-42236
--
EPSS 0.1%
DoS Agent Framework
n8n Patch: 1.123.32 CWE-770 16 3 ATLAS
AWAITING NVD

n8n: WebSocket auth bypass hijacks AI agent workflows

CVE-2026-42228
--
EPSS 0.1%
Auth Bypass Data Extraction Prompt Injection Agent Framework Plugin
n8n Patch: 1.123.32 CWE-862 16 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial