AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 167 results — Critical severity, no patchMLflow: XSS in recipe runner enables Jupyter RCE
CVE-2024-27133 MLflow: XSS in recipes enables client-side RCE
CVE-2024-27132 Gradio: unauthenticated LFI exposes full server filesystem
CVE-2024-0964 LlamaIndex: SQL injection in Text-to-SQL feature
CVE-2024-23751 Ray: unauthenticated RCE via job submission API
CVE-2023-48022 MLflow: auth bypass allows arbitrary account creation
CVE-2023-6014 MLflow: unauth file overwrite enables model poisoning
CVE-2023-6018 MLeap: zip slip in model loading enables RCE
CVE-2023-5245 LangChain: RCE bypass via __import__ in PAL chain
CVE-2023-44467 TorchServe: SSRF + RCE via unrestricted model URL loading
CVE-2023-43654 LangChain: RCE via numexpr evaluate injection
CVE-2023-39631 LangChain: RCE via malicious JSON prompt template
CVE-2023-36281 LangChain: RCE via unsanitized PythonAstREPL input
CVE-2023-39659 LangChain: RCE via unsandboxed LLM code execution
CVE-2023-38896 LangChain: RCE via unsanitized prompt parameter
CVE-2023-38860 LangChain PALChain: RCE via unsanitized exec() calls
CVE-2023-36095 MLflow: path traversal allows arbitrary file read
CVE-2023-3765 QuickAI: unauthenticated SQLi exposes OpenAI API keys
CVE-2023-3686 LangChain: RCE via PALChain unsanitized Python exec
CVE-2023-36188 LangChain: unauthenticated RCE via code injection
CVE-2023-36258 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert