AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,140

AI/ML CVEs Tracked

171

Critical

228

New This Week

2

In CISA KEV

Weekly CISO Take + top threats

Get the week's most critical AI security threats delivered every Monday. Free, no spam.

Latest AI Security Threats

Showing 50 of 450 results — High severity, no patch
HIGH CVE-2026-33484

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without...

Auth Bypass Data Extraction Privacy Violation Framework API
CVSS 7.5 langflow CWE-284
View details
HIGH CVE-2026-33053

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with...

Supply Chain Code Execution DoS Framework Agent API
CVSS 8.8 EPSS 0.0% langflow CWE-639
View details
HIGH CVE-2026-33236

NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

CVSS 8.1 EPSS 0.0% CWE-22
View details
HIGH CVE-2026-33155

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

EPSS 0.0% CWE-400
View details
HIGH CVE-2026-25750

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith...

Prompt Injection Data Leakage Code Execution Framework Agent API
CVSS 8.1 langsmith CWE-74
View details
HIGH CVE-2026-27905

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path...

Code Execution Framework Agent Model
CVSS 7.8 EPSS 0.0% bentoml CWE-59
View details
HIGH CVE-2026-28416

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP...

Data Extraction Code Execution Framework Model Training Data
CVSS 8.6 EPSS 0.0% gradio CWE-918
View details
HIGH CVE-2026-28414

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that...

Code Execution Data Extraction Framework API Model
CVSS 7.5 EPSS 0.0% gradio CWE-36
View details
HIGH CVE-2026-27498

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-94
View details
HIGH CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's...

Model Poisoning Code Execution Agent RAG API
CVSS 8.8 n8n CWE-89
View details
HIGH CVE-2026-2472

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

EPSS 0.1% CWE-79
View details
HIGH CVE-2026-26286

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions...

Data Extraction Code Execution Social Engineering Framework RAG Agent
CVSS 8.5 CWE-918
View details
HIGH CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose...

Data Extraction Code Execution Framework RAG API
CVSS 7.5 EPSS 0.0% keras CWE-73
View details
HIGH CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The...

Code Execution Social Engineering Agent RAG API
CVSS 7.2 n8n CWE-20
View details
HIGH CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or...

CVSS 8.8 n8n CWE-434
View details
HIGH CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating...

CVSS 8.1 n8n CWE-22
View details
HIGH CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to...

CVSS 7.7 n8n CWE-200
View details
HIGH CVE-2026-0599

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The...

CVSS 7.5 EPSS 0.2% CWE-400
View details
HIGH CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT...

CVSS 8.8 EPSS 0.1% CWE-94
View details
HIGH CVE-2026-24779

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the...

CVSS 7.1 EPSS 0.0% vllm CWE-918
View details
HIGH CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file...

CVSS 8.8 EPSS 0.0% pytorch CWE-94
View details
HIGH CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected...

EPSS 11.4% langflow CWE-829
View details
HIGH CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a...

CVSS 7.4 CWE-79
View details
HIGH CVE-2026-21852

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before...

CVSS 7.5 claude_code CWE-522
View details
HIGH CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVSS 7.5 ollama
View details
HIGH CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

CVSS 7.5 ollama
View details
HIGH CVE-2025-33233

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution,...

CVSS 7.8 CWE-94
View details
HIGH CVE-2025-15514

Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data...

CVSS 7.5 ollama CWE-395
View details
HIGH CVE-2024-58340

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method...

CVSS 7.5 langchain CWE-1333
View details
HIGH CVE-2024-58339

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query()...

CVSS 7.5 llamaindex CWE-770
View details
HIGH CVE-2024-14021

LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py....

CVSS 7.8 llamaindex CWE-502
View details
HIGH CVE-2026-22033

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

EPSS 0.0% label-studio CWE-79
View details
HIGH CVE-2026-22773

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3...

CVSS 7.5 EPSS 0.0% vllm CWE-770
View details
HIGH CVE-2026-0621

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded...

CVSS 7.5
View details
HIGH CVE-2025-67729

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

CVSS 8.8 EPSS 0.1% CWE-502
View details
HIGH CVE-2025-68664

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd()...

CVSS 8.2 EPSS 0.0% langchain_core CWE-502
View details
HIGH ACTIVELY EXPLOITED CVE-2025-68613

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their...

CVSS 8.8 n8n CWE-913
View details
HIGH CVE-2025-68478

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the...

CVSS 7.1 EPSS 0.1% langflow CWE-73
View details
HIGH CVE-2025-53000

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

EPSS 0.0% CWE-427
View details
HIGH CVE-2025-67644

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

CVSS 7.3 EPSS 0.0% CWE-89
View details
HIGH CVE-2025-33213

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to...

CVSS 8.8 CWE-502
View details
HIGH CVE-2025-65964

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation...

CVSS 8.8 n8n
View details
HIGH CVE-2025-34291

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with...

CVSS 8.8 EPSS 13.1% langflow CWE-346
View details
HIGH CVE-2025-66404

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes...

CVSS 8.8
View details
HIGH CVE-2025-66448

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm...

CVSS 8.8 EPSS 0.2% vllm CWE-94
View details
HIGH CVE-2025-62609

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer...

CVSS 7.5 EPSS 0.1% mlx CWE-476
View details
HIGH CVE-2025-12973

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function...

CVSS 7.2
View details
HIGH CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and...

CVSS 8.8 EPSS 0.1% vllm CWE-20
View details
HIGH CVE-2025-64439

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

EPSS 0.8% CWE-502
View details
HIGH CVE-2025-62726

n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n....

CVSS 8.8 n8n
View details

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial