AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 58 results — Critical severity, has patchopen-webui: LDAP auth bypass — full account takeover
CVE-2026-44551 vm2: sandbox escape via nesting:true enables RCE
CVE-2026-44007 Langflow: path traversal allows arbitrary directory deletion
CVE-2026-42048 LiteLLM has SQL Injection in Proxy API key verification
GHSA-r75f-5x8p-qvmc Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41264 Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
GHSA-v38x-c887-992f OpenClaw: Feishu webhook and card-action validation now fail closed
GHSA-xh72-v6v9-mwhc Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
GHSA-9qhq-v63v-fv3j Flowise CSVAgent: RCE via Python code injection
GHSA-9wc7-mj3f-74xv Flowise: RCE via MCP stdio command injection
CVE-2026-40933 PraisonAI: auth bypass enables browser session hijack
GHSA-8x8f-54wf-vv92 PraisonAI: RCE via malicious workflow YAML execution
GHSA-vc46-vw85-3wvm PraisonAI: path traversal allows arbitrary file write via recipe unpack
CVE-2026-40157 PraisonAI: supply chain RCE via unverified template exec
CVE-2026-40154 lollms: Stored XSS enables wormable account takeover
CVE-2026-1115 PraisonAI: RCE via shell injection in memory hooks executor
CVE-2026-40111 PraisonAI: RCE via shell injection in agent workflows
GHSA-2763-cj5r-c79m Marimo: pre-auth RCE via terminal WebSocket
GHSA-2679-6mx9-h9xc praisonaiagents: sandbox escape enables host RCE
CVE-2026-39888 PraisonAI: YAML deserialization enables unauthenticated RCE
CVE-2026-39890 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert