AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,625

AI/ML CVEs Tracked

230

Critical

87

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1625 results
HIGH EXPLOIT AVAIL

Flowise: unrestricted file upload enables persistent RCE

CVE-2026-41269
8.8
EPSS 0.1%
Code Execution Auth Bypass Data Extraction Agent Framework
flowise CWE-434 6 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: unauthenticated RCE via NODE_OPTIONS env injection

CVE-2026-41268
9.8
EPSS 0.7%
Code Execution Auth Bypass Agent Framework
flowise 6 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: mass assignment auth bypass in registration

CVE-2026-41267
9.8
EPSS 0.3%
Auth Bypass Data Extraction Privacy Violation Agent Framework
flowise CWE-639 5 ATLAS
HIGH EXPLOIT AVAIL

Flowise: unauthenticated API key exposure via chatbot config

CVE-2026-41266
7.5
EPSS 0.0%
Auth Bypass Data Extraction Data Leakage Agent Framework API
flowise CWE-200 6 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: RCE via prompt injection in Airtable Agent

CVE-2026-41265
9.8
EPSS 0.2%
Prompt Injection Code Execution Agent Framework
flowise 7 ATLAS
HIGH EXPLOIT AVAIL

Flowise: RCE via unsanitized input in AirtableAgent

CVE-2026-41138
8.8
EPSS 0.3%
Code Execution Prompt Injection Agent Framework
flowise CWE-94 4 ATLAS
HIGH EXPLOIT AVAIL

Flowise: RCE via CSVAgent unsanitized code injection

CVE-2026-41137
8.8
EPSS 0.3%
Code Execution Data Extraction Agent Framework
flowise 4 ATLAS
MEDIUM

n8n-mcp: bearer tokens exposed in HTTP transport logs

CVE-2026-41495
5.3
EPSS 0.0%
Data Leakage Auth Bypass Agent API Plugin
n8n-mcp Patch: 2.47.11 CWE-532 16 4 ATLAS
HIGH

engramx: CSRF injects persistent prompts into AI agents

GHSA-2r2p-4cgf-hv7h
--
Prompt Injection Data Extraction Auth Bypass Agent Plugin
CWE-306 5 ATLAS
HIGH

InstructLab: RCE via hardcoded trust_remote_code flag

CVE-2026-6859
8.8
EPSS 0.1%
Supply Chain Code Execution Model Training Data
CWE-829 5 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: prompt injection → unsandboxed RCE via CSV Agent

CVE-2026-41264
9.8
EPSS 0.3%
Prompt Injection Code Execution Agent Framework
flowise-components Patch: 3.1.0 CWE-184 5 ATLAS
MEDIUM

nbconvert: path traversal exfiltrates files via HTML export

CVE-2026-39378
6.5
EPSS 0.0%
Data Extraction Supply Chain Framework Plugin
nbconvert Patch: 7.17.1 CWE-22 2.9K 4 ATLAS
MEDIUM

nbconvert: path traversal enables arbitrary file write

CVE-2026-39377
6.5
EPSS 0.0%
Supply Chain Code Execution Framework
nbconvert Patch: 7.17.1 CWE-22 2.9K 3 ATLAS
HIGH

Claude Code: sandbox escape via symlink allows arbitrary write

CVE-2026-39861
--
EPSS 0.2%
Code Execution Prompt Injection Auth Bypass Agent
@anthropic-ai/claude-code Patch: 2.1.64 CWE-22 5 ATLAS
MEDIUM EXPLOIT AVAIL

FastChat: control flow flaw corrupts arena comparison

CVE-2026-6608
5.3
EPSS 0.0%
Adversarial Examples Supply Chain Framework API
fschat CWE-670 679 3 ATLAS
LOW EXPLOIT AVAIL

Langflow: stored XSS in chat message editor

CVE-2026-6600
3.5
EPSS 0.0%
Code Execution Data Extraction Framework Agent
langflow CWE-79 4 ATLAS
MEDIUM EXPLOIT AVAIL

Langflow: MCP config injection via X-Forwarded-For header

CVE-2026-6599
6.3
EPSS 0.0%
Auth Bypass Code Execution Supply Chain Framework Agent Plugin
langflow CWE-74 4 ATLAS
MEDIUM EXPLOIT AVAIL

Langflow: cleartext auth storage exposes API keys

CVE-2026-6598
4.3
EPSS 0.0%
Data Extraction Privacy Violation Framework
langflow Patch: 1.9.1 CWE-312 5 ATLAS
LOW EXPLOIT AVAIL

langflow: Plaintext credential storage via Flow API

CVE-2026-6597
2.7
EPSS 0.0%
Data Leakage Data Extraction Framework API
langflow CWE-255 5 ATLAS
HIGH EXPLOIT AVAIL

Langflow: unauthenticated file upload allows RCE

CVE-2026-6596
7.3
EPSS 0.1%
Code Execution Auth Bypass Framework Agent
langflow-base Patch: 1.9.1 CWE-284 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial