AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

230

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
Severity CVE ID Summary CVSS EPSS Package Date
UNKN CVE-2026-42229 n8n: SQL injection in SeaTable node leaks restricted rows 0.1% n8n Apr 29 UNKN CVE-2026-42230 n8n: MCP OAuth open redirect enables phishing 0.0% n8n Apr 29 UNKN CVE-2026-42233 n8n: SQL injection in Oracle node allows data exfiltration 0.1% n8n Apr 29 UNKN CVE-2026-42237 n8n: SQL injection in Snowflake/MySQL nodes bypasses fix 0.0% n8n Apr 29 UNKN CVE-2026-42249 Ollama: path traversal + unsigned update = silent RCE 0.0% ollama Apr 29 UNKN CVE-2026-42248 Ollama: silent auto-update bypasses signature check on Windows 0.0% ollama Apr 29 MEDI E CVE-2026-7141 vllm: uninitialized KV cache memory leaks inference data 5.6 0.1% vllm Apr 27 LOW E CVE-2026-7020 Ollama: path traversal in tensor model transfer handler 3.7 0.1% ollama Apr 26 MEDI GHSA-7jm2-g593-4qrc openclaw: config guard bypass, persistent settings mutation openclaw Apr 25 MEDI GHSA-qrp5-gfw2-gxv4 openclaw: tool policy bypass via bundled MCP/LSP tools openclaw Apr 25 MEDI GHSA-h2vw-ph2c-jvwf OpenClaw: env injection exposes MiniMax API key openclaw Apr 25 LOW GHSA-j4c5-89f5-f3pm openclaw: SSRF policy bypass in CDP browser profile creation openclaw Apr 25 LOW GHSA-xrq9-jm7v-g9h7 OpenClaw: auth bypass enables cross-device session hijack openclaw Apr 25 LOW GHSA-c4qg-j8jg-42q5 openclaw: SSRF in QQBot media upload bypasses validation openclaw Apr 25 MEDI GHSA-mj59-h3q9-ghfh openclaw: env var injection via MCP stdio config openclaw Apr 25 LOW GHSA-57r2-h2wj-g887 openclaw: trust-label bypass amplifies prompt injection openclaw Apr 25 MEDI GHSA-hxvm-xjvf-93f3 openclaw: env namespace injection steers agent runtime openclaw Apr 25 MEDI GHSA-72q8-jcmc-97wx openclaw: DM policy bypass via Feishu card-action callbacks openclaw Apr 25 LOW GHSA-v8qf-fr4g-28p2 OpenClaw: auth scope bypass exposes assistant-media files openclaw Apr 25 MEDI GHSA-2xcp-x87w-q377 openclaw: session key auth bypass in webhook routing openclaw Apr 25

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial