AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 225 results — Critical severity
CRITICAL EXPLOIT AVAIL

langchaingo: Jinja2 SSTI allows host filesystem read

CVE-2025-9556
9.8
EPSS 0.1%
Code Execution Data Extraction Framework Agent
5 ATLAS
CRITICAL EXPLOIT AVAIL

n8n-workflows: path traversal in download_workflow endpoint

CVE-2025-55526
9.1
EPSS 0.6%
Data Extraction Auth Bypass Code Execution Agent Framework API
fastapi 16 5 ATLAS
CRITICAL EXPLOIT AVAIL

ExecuTorch: OOB read in model loader enables RCE

CVE-2025-54950
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-125 2 4 ATLAS
CRITICAL

ExecuTorch: integer overflow in model load → RCE

CVE-2025-30405
9.8
EPSS 0.2%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-190 2 4 ATLAS
CRITICAL

ExecuTorch: integer overflow RCE on model load

CVE-2025-30404
9.8
EPSS 0.2%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-190 2 5 ATLAS
CRITICAL

ExecuTorch: heap buffer overflow RCE via model loading

CVE-2025-54949
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Model
executorch Patch: 0.7.0 CWE-122 2 5 ATLAS
CRITICAL

ExecuTorch: heap buffer overflow RCE in model loading

CVE-2025-54951
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-122 2 4 ATLAS
CRITICAL EXPLOIT AVAIL

Azure OpenAI: SSRF EoP, no auth required (CVSS 10)

CVE-2025-53767
10.0
EPSS 0.5%
Auth Bypass Data Extraction Privacy Violation API Inference
azure_openai 13.6K 6 ATLAS
CRITICAL EXPLOIT AVAIL

ChatGLM-Webui: arbitrary file read, no auth required

CVE-2025-45150
9.8
EPSS 0.1%
Data Extraction Auth Bypass Framework API
langchain-chatglm-webui 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

BentoML: unauthenticated SSRF via file upload URLs

CVE-2025-54381
9.9
EPSS 0.7%
Supply Chain Data Extraction Auth Bypass Framework Inference API
bentoml CWE-918 22 5 ATLAS
CRITICAL EXPLOIT AVAIL

LangChain GmailToolkit: indirect prompt injection to RCE

CVE-2025-46059
9.8
EPSS 0.3%
Prompt Injection Code Execution Data Extraction Framework Agent Plugin
6 ATLAS
CRITICAL EXPLOIT AVAIL

smolagents: sandbox escape enables unauthenticated RCE

CVE-2025-5120
10.0
EPSS 0.4%
Code Execution Supply Chain Data Leakage Framework Agent
smolagents CWE-94 86 5 ATLAS
CRITICAL EXPLOIT AVAIL

Langchain-Chatchat: path traversal in KB upload

CVE-2025-6853
9.8
EPSS 0.6%
Code Execution Data Extraction Supply Chain Framework RAG
langchain-chatchat CWE-22 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

LLaMA-Factory: RCE via unsafe checkpoint deserialization

CVE-2025-53002
9.8
EPSS 4.2%
Code Execution Supply Chain Framework Model
llamafactory CWE-94 1 6 ATLAS
CRITICAL EXPLOIT AVAIL

LangChain RequestsToolkit: SSRF exposes cloud metadata

CVE-2025-2828
10.0
EPSS 0.2%
Data Extraction Auth Bypass Framework Agent
langchain CWE-918 2.6K 5 ATLAS
CRITICAL EXPLOIT AVAIL

llama_index: SQL injection in vector store integrations

CVE-2025-1793
9.8
EPSS 0.1%
Data Extraction Data Leakage Supply Chain Framework RAG
llama-index Patch: 0.12.28 CWE-89 229 5 ATLAS
CRITICAL EXPLOIT AVAIL

vLLM: RCE via exposed TCPStore in distributed inference

CVE-2025-47277
9.8
EPSS 0.9%
Code Execution Data Extraction Inference Framework
vllm CWE-502 126 4 ATLAS
CRITICAL EXPLOIT AVAIL

browser-use: URL allowlist bypass enables SSRF in agents

CVE-2025-47241
9.3
EPSS 0.2%
Auth Bypass Data Extraction Agent Framework
browser-use Patch: 0.1.45 CWE-647 65 5 ATLAS
CRITICAL EXPLOIT AVAIL

vLLM: RCE via pickle deserialization on ZeroMQ

CVE-2025-32444
9.8
EPSS 2.5%
Code Execution Supply Chain Inference Framework
vllm CWE-502 126 5 ATLAS
CRITICAL

vLLM: RCE via malicious model, PyTorch < 2.6 bypass

GHSA-ggpf-24jw-3fcw
9.8
Code Execution Supply Chain Framework Inference Model
vllm Patch: 0.8.0 CWE-1395 126 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial