AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 485 results — High severity, no patch
HIGH

LiteLLM: RCE via MCP test endpoint command injection

CVE-2026-42271
8.8
EPSS 0.0%
Code Execution Auth Bypass Framework API Inference
litellm CWE-77 4 5 ATLAS
HIGH

PPTAgent: eval injection enables RCE via LLM prompt injection

CVE-2026-42079
8.6
EPSS 0.0%
Prompt Injection Code Execution Agent Framework
CWE-95 5 ATLAS
HIGH

Langflow: RCE exposes API keys and DB credentials

CVE-2026-6543
8.8
EPSS 0.0%
Code Execution Data Extraction Supply Chain Framework Agent
langflow CWE-94 5 ATLAS
HIGH

Langflow Desktop: IDOR leaks user images unauthenticated

CVE-2026-4503
7.5
EPSS 0.1%
Privacy Violation Data Extraction Auth Bypass Framework Agent
langflow CWE-639 3 ATLAS
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST...

CVE-2026-41279
7.5
EPSS 0.1%
flowise CWE-639
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns...

CVE-2026-41278
7.5
EPSS 0.0%
flowise CWE-200
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore...

CVE-2026-41277
8.8
EPSS 0.1%
flowise CWE-284
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on...

CVE-2026-41275
7.5
EPSS 0.0%
flowise CWE-319
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass...

CVE-2026-41273
8.2
EPSS 0.1%
flowise CWE-306
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and...

CVE-2026-41272
7.1
EPSS 0.0%
flowise
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability...

CVE-2026-41271
8.3
EPSS 0.1%
flowise CWE-918
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass...

CVE-2026-41270
8.3
EPSS 0.0%
flowise CWE-284
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be...

CVE-2026-41269
8.8
EPSS 0.1%
flowise CWE-434
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive...

CVE-2026-41266
7.5
EPSS 0.0%
flowise CWE-200
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in...

CVE-2026-41138
8.8
EPSS 0.3%
flowise CWE-94
HIGH EXPLOIT AVAIL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read...

CVE-2026-41137
8.8
EPSS 0.3%
flowise
HIGH

engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection

GHSA-2r2p-4cgf-hv7h
--
CWE-306
HIGH

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote...

CVE-2026-6859
8.8
EPSS 0.1%
CWE-829
HIGH

paperclipai: connector trust bypass enables Gmail read/write

GHSA-gqqj-85qm-8qhf
8.7
Auth Bypass Privacy Violation Data Extraction Agent Plugin API
paperclipai CWE-284 3.5K 6 ATLAS
HIGH

LangChain-ChatChat: RCE via unauthenticated MCP interface

CVE-2026-30617
8.6
EPSS 0.2%
Code Execution Auth Bypass Supply Chain Agent Framework Plugin
6 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial