AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

76

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 220 results — Medium severity, has patch
MEDIUM

n8n: stored XSS via malicious OAuth2 Authorization URL

GHSA-364x-8g5j-x2pr
5.4
Code Execution Data Extraction Social Engineering Agent Framework Plugin
n8n Patch: 2.8.0 CWE-79 16 7 ATLAS
MEDIUM

n8n: Stored XSS in Chat Trigger via CSS injection

GHSA-3c7f-5hgj-h279
5.4
Code Execution Data Extraction Agent Framework
n8n Patch: 1.123.27 CWE-79 16 6 ATLAS
MEDIUM

n8n: stored XSS enables phishing via Form Node

GHSA-w673-8fjw-457c
4.1
Social Engineering Data Extraction Agent Framework
n8n Patch: 2.12.0 CWE-79 16 4 ATLAS
MEDIUM

n8n: Stored XSS in Form Trigger enables phishing

GHSA-q4fm-pjq6-m63g
5.4
Social Engineering Data Extraction Agent Framework
n8n Patch: 2.11.2 CWE-79 16 4 ATLAS
MEDIUM EXPLOIT AVAIL

open-webui: missing authz allows cross-KB file deletion

CVE-2026-29070
5.4
EPSS 0.0%
Auth Bypass DoS RAG Framework
open-webui Patch: 0.8.6 CWE-862 4 ATLAS
MEDIUM EXPLOIT AVAIL

Open WebUI: path traversal leaks server filesystem path

CVE-2026-28786
4.3
EPSS 0.0%
Data Extraction Data Leakage Framework API
open-webui Patch: 0.8.6 CWE-22 4 ATLAS
MEDIUM

Streamlit: SSRF leaks NTLMv2 creds via UNC path

CVE-2026-33682
4.7
EPSS 0.0%
Data Leakage Auth Bypass Framework
Streamlit Patch: 1.54.0 CWE-918 2.8K 4 ATLAS
MEDIUM

n8n: LDAP injection enables auth bypass in workflows

CVE-2026-33751
4.8
EPSS 0.0%
Auth Bypass Data Extraction Agent Framework
n8n Patch: 1.123.27 CWE-90 16 3 ATLAS
MEDIUM

n8n: secrets vault bypass exposes credentials to low-priv users

CVE-2026-33722
5.3
EPSS 0.0%
Auth Bypass Data Extraction Data Leakage Agent Framework API
n8n Patch: 1.123.23 CWE-863 16 5 ATLAS
MEDIUM

n8n: OAuth state forgery hijacks user credentials

CVE-2026-33720
4.2
EPSS 0.0%
Auth Bypass Social Engineering Data Extraction Agent Framework API
n8n Patch: 2.8.0 CWE-863 16 6 ATLAS
MEDIUM

n8n: uninitialized buffer leaks secrets via Task Runner

CVE-2026-27496
6.5
EPSS 0.0%
Data Leakage Data Extraction Agent Framework
n8n Patch: 1.123.22 CWE-908 16 4 ATLAS
MEDIUM

fickling: Allowlist Bypass evades input filtering

GHSA-5cxw-w2xg-2m8h
--
Supply Chain Data Extraction Code Execution Framework Model Training Data
fickling Patch: 0.1.10 CWE-184 57 5 ATLAS
MEDIUM

fickling: Allowlist Bypass evades input filtering

GHSA-r48f-3986-4f9c
--
Data Extraction Code Execution Auth Bypass Framework
fickling Patch: 0.1.10 CWE-184 57 5 ATLAS
MEDIUM

langgraph: Deserialization enables RCE

CVE-2026-28277
6.8
EPSS 0.3%
Code Execution Data Leakage Supply Chain Framework Agent
langgraph Patch: 1.0.10 CWE-502 3.1K 5 ATLAS
MEDIUM

langgraph-checkpoint: Deserialization enables RCE

CVE-2026-27794
6.6
EPSS 0.4%
Code Execution Supply Chain Framework Agent
langgraph-checkpoint Patch: 4.0.0 CWE-502 3.1K 4 ATLAS
MEDIUM

fickling: Allowlist Bypass evades input filtering

GHSA-mhc9-48gj-9gp3
--
Supply Chain Code Execution Framework Model
fickling Patch: 0.1.8 CWE-184 57 7 ATLAS
MEDIUM EXPLOIT AVAIL

ray: Missing Auth allows unauthenticated access

CVE-2026-27482
5.9
EPSS 0.1%
Auth Bypass DoS Framework Inference
ray Patch: 2.54.0 CWE-306 847 4 ATLAS
MEDIUM

pydantic-ai: Path Traversal enables file access

CVE-2026-25640
5.4
EPSS 0.0%
Code Execution Data Extraction Framework Agent
pydantic-ai-slim Patch: 1.51.0 CWE-22 416 5 ATLAS
MEDIUM

sagemaker: security flaw enables exploitation

CVE-2026-1778
5.9
EPSS 0.0%
Supply Chain Code Execution Inference Framework
sagemaker Patch: 3.1.1 CWE-295 51 5 ATLAS
MEDIUM

picklescan: Deserialization enables RCE

GHSA-m7j5-r2p5-c39r
--
Supply Chain DoS Code Execution Framework Model Training Data
picklescan Patch: 1.0.1 CWE-502 3 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial