AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 1140 results
MEDIUM CVE-2025-48944

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to...

CVSS 6.5 EPSS 0.1% vllm CWE-20
View details
MEDIUM CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema as a Guided Param...

CVSS 6.5 EPSS 0.1% vllm CWE-248
View details
MEDIUM CVE-2025-48887

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file...

CVSS 6.5 EPSS 0.1% vllm CWE-1333
View details
HIGH CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an...

CVSS 7.5 EPSS 0.9% gradio CWE-434
View details
HIGH CVE-2025-46722

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a...

CVSS 7.3 EPSS 0.1% vllm CWE-1023
View details
LOW CVE-2025-46570

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the...

CVSS 2.6 EPSS 0.1% vllm CWE-203
View details
LOW CVE-2025-5320

A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument...

CVSS 3.7 EPSS 0.0% gradio CWE-345
View details
MEDIUM GHSA-j828-28rj-hfhp

vLLM vulnerable to Regular Expression Denial of Service

CVSS 4.3 vllm Patch: 0.9.0 CWE-1333
View details
HIGH CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load...

CVSS 7.8 EPSS 0.1% CWE-502
View details
CRITICAL CVE-2025-47277

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer...

CVSS 9.8 EPSS 0.9% vllm CWE-502
View details
HIGH CVE-2025-2099

A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS)...

CVSS 7.5 EPSS 0.1% transformers CWE-1333
View details
UNKNOWN CVE-2025-1975

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to...

ollama
View details
HIGH CVE-2025-47783

label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

EPSS 0.2% label-studio Patch: 1.18.0 CWE-79
View details
HIGH CVE-2025-1752

LlamaIndex Vulnerable to Denial of Service (DoS)

CVSS 7.5 EPSS 0.2% llama-index Patch: 0.12.21 CWE-400
View details
HIGH CVE-2025-0649

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVSS 7.5 tensorflow_serving CWE-787
View details
HIGH CVE-2025-30165

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM...

CVSS 8.0 EPSS 1.3% vllm CWE-502
View details
LOW CVE-2025-4287

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation...

CVSS 3.3
View details
CRITICAL CVE-2025-47241

Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL

CVSS 9.3 EPSS 0.2% browser-use Patch: 0.1.45 CWE-647
View details
HIGH CVE-2025-46567

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script...

CVSS 7.8 EPSS 0.2% llamafactory Patch: 0.9.3 CWE-502
View details
HIGH CVE-2025-46560

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input...

CVSS 7.5 EPSS 0.6% vllm CWE-1333
View details
CRITICAL CVE-2025-32444

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote...

CVSS 9.8 EPSS 2.5% vllm CWE-502
View details
HIGH CVE-2025-30202

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ...

CVSS 7.5 EPSS 0.4% vllm CWE-770
View details
MEDIUM CVE-2025-1194

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the...

CVSS 6.5 EPSS 0.1% transformers CWE-1333
View details
MEDIUM CVE-2025-46343

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary...

CVSS 5.4 n8n
View details
CRITICAL GHSA-ggpf-24jw-3fcw

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVSS 9.8 vllm Patch: 0.8.0 CWE-1395
View details
CRITICAL CVE-2025-32434

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command...

CVSS 9.8 EPSS 1.2% pytorch CWE-502
View details
MEDIUM CVE-2025-3730

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation...

CVSS 5.5 EPSS 0.1% pytorch CWE-404
View details
MEDIUM GHSA-hf3c-wxg2-49q9

vLLM vulnerable to Denial of Service by abusing xgrammar cache

CVSS 6.5 vllm Patch: 0.8.4 CWE-770
View details
CRITICAL CVE-2025-32428

TigerVNC accessible via the network and not just via a UNIX socket as intended

EPSS 0.2% CWE-668
View details
CRITICAL CVE-2025-32375

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting...

CVSS 9.8 EPSS 67.3% bentoml CWE-502
View details
MEDIUM CVE-2025-32381

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

CVSS 6.5 EPSS 0.3% xgrammar Patch: 0.1.18 CWE-770
View details
MEDIUM GHSA-v7x6-rv5q-mhwc

Picklescan missing detection when calling built-in python library function timeit.timeit()

picklescan Patch: 0.0.25 CWE-184
View details
MEDIUM GHSA-fj43-3qmq-673f

Picklescan failed to detect to some unsafe global function in Numpy library

picklescan Patch: 0.0.25 CWE-502
View details
HIGH CVE-2025-46417

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

EPSS 0.2% picklescan Patch: 0.0.25 CWE-184
View details
CRITICAL ACTIVELY EXPLOITED CVE-2025-3248

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary...

CVSS 9.8 EPSS 92.5% langflow CWE-94
View details
CRITICAL CVE-2025-27520

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been...

CVSS 9.8 EPSS 87.3% bentoml CWE-502
View details
HIGH CVE-2025-30370

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

CVSS 7.4 EPSS 0.1% CWE-78
View details
LOW CVE-2025-3136

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file...

CVSS 3.3 pytorch CWE-787
View details
MEDIUM CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is...

CVSS 5.5 pytorch
View details
MEDIUM CVE-2025-31843

Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for...

CVSS 4.3
View details
MEDIUM CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption....

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory...

CVSS 5.3 pytorch
View details
MEDIUM CVE-2025-2953

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of...

CVSS 5.5 EPSS 0.2% pytorch CWE-404
View details
HIGH CVE-2025-30358

Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and...

CVSS 8.1 EPSS 3.1% CWE-915
View details
CRITICAL CVE-2024-12029

InvokeAI Deserialization of Untrusted Data vulnerability

CVSS 9.8 EPSS 49.1% CWE-502
View details
HIGH CVE-2025-0628

LiteLLM Has an Improper Authorization Vulnerability

CVSS 8.1 EPSS 0.1% litellm Patch: 1.61.15 CWE-266
View details
HIGH CVE-2025-0330

LiteLLM Has a Leakage of Langfuse API Keys

CVSS 7.5 EPSS 0.1% litellm CWE-1230
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial