AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severityOpenClaw: pre-auth signature bypass enables pairing DoS
GHSA-h43v-27wg-5mf9 OpenClaw: exec allowlist bypass via shell init-file options
GHSA-wpc6-37g7-8q4w openclaw: sandbox escape via mirror mode hook execution
GHSA-42mx-vp8m-j7qh openclaw: auth bypass exposes agent session visibility
GHSA-fwjq-xwfj-gv75 openclaw: privilege escalation to admin voice config persistence
GHSA-3q42-xmxv-9vfr openclaw: SSRF in marketplace plugin download
GHSA-vjx8-8p7h-82gr openclaw: media download bypass exhausts disk storage
GHSA-4g5x-2jfc-xm98 openclaw: operator scope bypass in phone arm/disarm cmds
GHSA-h2v7-xc88-xx8c MLflow: auth bypass exposes model artifacts across experiments
CVE-2026-33866 MLflow: stored XSS via MLmodel YAML artifact upload
CVE-2026-33865 HuggingFace Transformers: RCE via malicious checkpoint load
CVE-2026-1839 OpenClaw: script preflight bypass enables unsafe exec
CVE-2026-34425 kedro-datasets: path traversal enables arbitrary file write
CVE-2026-35492 Ollama: SSRF in Model Pull API enables network pivot
CVE-2026-5530 Directus: cleartext storage exposes AI API keys
GHSA-mvv8-v4jj-g47j vLLM: OOM DoS via unbounded video frame decoding
CVE-2026-34755 vLLM: SSRF in batch API exposes cloud metadata endpoints
CVE-2026-34753 ltiauthenticator: OAuth nonce leak causes server DoS
CVE-2026-34052 JupyterHub: open redirect enables post-login phishing
CVE-2026-33709 vLLM: DoS via unbounded n parameter causes OOM crash
CVE-2026-34756 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert