AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 570 results — Medium severity
MEDIUM

OpenClaw: SSRF in marketplace fetch hits internal AI infra

GHSA-9q7v-8mr7-g23p
--
Supply Chain Data Extraction Auth Bypass Plugin Inference Agent
openclaw Patch: 2026.3.31 CWE-918 4 4 ATLAS
MEDIUM

vLLM: audio downmix mismatch enables adversarial input

CVE-2026-34760
5.9
EPSS 0.1%
Adversarial Examples Supply Chain Inference Framework
CWE-20 4 ATLAS
MEDIUM EXPLOIT AVAIL

ONNX: symlink traversal reads host files via model loading

CVE-2026-34447
5.5
EPSS 0.0%
Supply Chain Data Extraction Framework Model
onnx Patch: 1.21.0 CWE-22 1.2K 5 ATLAS
MEDIUM

ONNX: hardlink path traversal leaks sensitive files

CVE-2026-34446
4.7
EPSS 0.0%
Supply Chain Data Extraction Framework Model
onnx Patch: 1.21.0 CWE-22 1.2K 4 ATLAS
MEDIUM

Anthropic SDK: TOCTOU symlink escape in async memory tool

CVE-2026-34452
--
EPSS 0.0%
Code Execution Data Extraction Auth Bypass Framework Agent API
anthropic Patch: 0.87.0 CWE-59 4.8K 5 ATLAS 17 incidents
MEDIUM

anthropic-ai/sdk: memory tool path traversal escape

CVE-2026-34451
--
EPSS 0.1%
Prompt Injection Data Extraction Code Execution Framework Agent API
@anthropic-ai/sdk Patch: 0.81.0 CWE-22 240 6 ATLAS
MEDIUM

anthropic-sdk: insecure file perms expose agent memory

CVE-2026-34450
--
EPSS 0.0%
Data Leakage Model Poisoning Data Extraction Agent Framework API
anthropic Patch: 0.87.0 CWE-276 4.8K 4 ATLAS 17 incidents
MEDIUM

OpenClaw: HTTP scope bypass enables model enumeration

GHSA-68f8-9mhj-h2mp
--
Auth Bypass Data Extraction API Inference
openclaw Patch: 2026.3.24 CWE-284 4 4 ATLAS 2 incidents
MEDIUM

openclaw: webhook rate-limit bypass enables token brute-force

CVE-2026-35646
--
EPSS 0.1%
Auth Bypass Data Extraction Agent Plugin
openclaw Patch: 2026.3.28 CWE-307 4 4 ATLAS 1 incident
MEDIUM

openclaw: unauthenticated webhook parsing enables DoS

CVE-2026-35640
--
EPSS 0.1%
DoS Agent
openclaw Patch: 2026.3.28 CWE-400 4 3 ATLAS
MEDIUM

openclaw: auth bypass exposes agent session history via HTTP

CVE-2026-35657
--
EPSS 0.0%
Auth Bypass Data Extraction Agent API
openclaw Patch: 2026.3.25 CWE-639 4 3 ATLAS 1 incident
MEDIUM

DOMPurify: mXSS bypass achieves XSS via parse-context switch

GHSA-h8r8-wccr-v5f2
--
Code Execution Supply Chain Framework
CWE-79 5 ATLAS
MEDIUM

n8n: stored XSS via malicious OAuth2 Authorization URL

GHSA-364x-8g5j-x2pr
5.4
Code Execution Data Extraction Social Engineering Agent Framework Plugin
n8n Patch: 2.8.0 CWE-79 16 7 ATLAS
MEDIUM

n8n: Stored XSS in Chat Trigger via CSS injection

GHSA-3c7f-5hgj-h279
5.4
Code Execution Data Extraction Agent Framework
n8n Patch: 1.123.27 CWE-79 16 6 ATLAS
MEDIUM

n8n: stored XSS enables phishing via Form Node

GHSA-w673-8fjw-457c
4.1
Social Engineering Data Extraction Agent Framework
n8n Patch: 2.12.0 CWE-79 16 4 ATLAS
MEDIUM

n8n: Stored XSS in Form Trigger enables phishing

GHSA-q4fm-pjq6-m63g
5.4
Social Engineering Data Extraction Agent Framework
n8n Patch: 2.11.2 CWE-79 16 4 ATLAS
MEDIUM EXPLOIT AVAIL

smolagents: code injection via incomplete sandbox fix

CVE-2026-4963
6.3
EPSS 0.0%
Code Execution Supply Chain Agent Framework
smolagents CWE-74 88 5 ATLAS
MEDIUM EXPLOIT AVAIL

open-webui: missing authz allows cross-KB file deletion

CVE-2026-29070
5.4
EPSS 0.0%
Auth Bypass DoS RAG Framework
open-webui Patch: 0.8.6 CWE-862 4 ATLAS
MEDIUM EXPLOIT AVAIL

Open WebUI: path traversal leaks server filesystem path

CVE-2026-28786
4.3
EPSS 0.0%
Data Extraction Data Leakage Framework API
open-webui Patch: 0.8.6 CWE-22 4 ATLAS
MEDIUM

Streamlit: SSRF leaks NTLMv2 creds via UNC path

CVE-2026-33682
4.7
EPSS 0.0%
Data Leakage Auth Bypass Framework
Streamlit Patch: 1.54.0 CWE-918 2.8K 4 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial