AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 220 results — Medium severity, has patchn8n: stored XSS via malicious OAuth2 Authorization URL
GHSA-364x-8g5j-x2pr n8n: Stored XSS in Chat Trigger via CSS injection
GHSA-3c7f-5hgj-h279 n8n: stored XSS enables phishing via Form Node
GHSA-w673-8fjw-457c n8n: Stored XSS in Form Trigger enables phishing
GHSA-q4fm-pjq6-m63g open-webui: missing authz allows cross-KB file deletion
CVE-2026-29070 Open WebUI: path traversal leaks server filesystem path
CVE-2026-28786 Streamlit: SSRF leaks NTLMv2 creds via UNC path
CVE-2026-33682 n8n: LDAP injection enables auth bypass in workflows
CVE-2026-33751 n8n: secrets vault bypass exposes credentials to low-priv users
CVE-2026-33722 n8n: OAuth state forgery hijacks user credentials
CVE-2026-33720 n8n: uninitialized buffer leaks secrets via Task Runner
CVE-2026-27496 fickling: Allowlist Bypass evades input filtering
GHSA-5cxw-w2xg-2m8h fickling: Allowlist Bypass evades input filtering
GHSA-r48f-3986-4f9c langgraph: Deserialization enables RCE
CVE-2026-28277 langgraph-checkpoint: Deserialization enables RCE
CVE-2026-27794 fickling: Allowlist Bypass evades input filtering
GHSA-mhc9-48gj-9gp3 ray: Missing Auth allows unauthenticated access
CVE-2026-27482 pydantic-ai: Path Traversal enables file access
CVE-2026-25640 sagemaker: security flaw enables exploitation
CVE-2026-1778 picklescan: Deserialization enables RCE
GHSA-m7j5-r2p5-c39r Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert