AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 220 results — Medium severity, has patch
MEDIUM

mistune: XSS via unescaped heading id= attribute

CVE-2026-44897
6.1
Code Execution Data Extraction Framework RAG
mistune Patch: 3.2.1 CWE-79 467 4 ATLAS
MEDIUM

open-webui: XSS in pending overlay enables session hijack

CVE-2026-44568
4.8
Data Extraction Code Execution Social Engineering Inference Framework
open-webui Patch: 0.9.0 CWE-79 4 ATLAS
MEDIUM

open-webui: RAG auth bypass exposes private files

CVE-2026-44560
6.5
Auth Bypass Data Extraction Privacy Violation RAG API Framework
open-webui Patch: 0.9.0 CWE-862 5 ATLAS
MEDIUM

open-webui: auth bypass exposes private group channels

CVE-2026-44561
5.4
Auth Bypass Data Extraction Privacy Violation API
open-webui Patch: 0.9.0 CWE-284 4 ATLAS
MEDIUM

open-webui: auth bypass in collaborative doc editing

CVE-2026-44564
5.4
Auth Bypass Prompt Injection DoS API Framework
open-webui Patch: 0.9.0 CWE-863 4 ATLAS
MEDIUM

open-webui: auth bypass exposes restricted LLM models

CVE-2026-44563
5.4
Auth Bypass Data Extraction Inference API
open-webui Patch: 0.9.0 CWE-862 5 ATLAS
MEDIUM

open-webui: missing authz enables model hijacking

CVE-2026-44562
6.5
Auth Bypass Model Poisoning Data Extraction Model API Framework
open-webui Patch: 0.9.0 CWE-862 5 ATLAS
MEDIUM

open-webui: private channel member list exposed to any user

CVE-2026-44559
4.3
Auth Bypass Data Extraction Privacy Violation API Framework
open-webui Patch: 0.9.0 CWE-862 4 ATLAS
MEDIUM

open-webui: auth bypass exposes all knowledge base metadata

CVE-2026-44557
4.3
Auth Bypass Data Extraction Privacy Violation RAG Framework API
open-webui Patch: 0.9.0 CWE-200 5 ATLAS
MEDIUM

open-webui: permission bypass exposes channels publicly

CVE-2026-44558
5.4
Auth Bypass Data Leakage API Framework
open-webui Patch: 0.9.0 CWE-863 3 ATLAS
MEDIUM

open-webui: mass assignment enables cross-user folder injection

CVE-2026-44550
5.0
Auth Bypass Social Engineering Privacy Violation Framework API
open-webui Patch: 0.9.0 CWE-862 4 ATLAS
MEDIUM

BentoML: symlink traversal exfiltrates host secrets at build

CVE-2026-40610
5.5
Data Extraction Supply Chain Framework
bentoml Patch: 1.4.39 CWE-59 23 4 ATLAS
MEDIUM

@axonflow/openclaw: credential exposure via insecure file permissions

GHSA-cqmh-pcgr-q42f
5.5
Data Leakage Auth Bypass Privacy Violation Plugin Agent
@axonflow/openclaw Patch: 2.0.0 CWE-552 4 5 ATLAS
MEDIUM

vLLM: speculative decoding DoS via penalty params

CVE-2026-44223
6.5
DoS Inference
vllm Patch: 0.20.0 CWE-131 127 2 ATLAS
MEDIUM

vLLM: token injection DoS via multimodal placeholders

CVE-2026-44222
6.5
DoS Prompt Injection Inference Model Framework
vllm Patch: 0.20.0 CWE-129 127 5 ATLAS
MEDIUM

openclaw: stale webhook secret survives credential rotation

GHSA-q8ff-7ffm-m3r9
6.0
Auth Bypass Agent Plugin
openclaw Patch: 2026.4.23 CWE-613 4 3 ATLAS 1 incident
MEDIUM

JupyterHub: CSRF bypass on spawn and share endpoints

CVE-2026-40864
5.4
Auth Bypass DoS Framework
jupyterhub Patch: 5.4.5 CWE-352 1.9K 4 ATLAS
MEDIUM

jupyter-server: auth cookie survives password reset

CVE-2026-40934
6.8
EPSS 0.1%
Auth Bypass Data Extraction Framework API
jupyter-server Patch: 2.18.0 CWE-613 1.9K 4 ATLAS
MEDIUM

jupyter-server: Open redirect enables credential phishing

CVE-2025-61669
--
EPSS 0.0%
Social Engineering Auth Bypass Framework API
jupyter-server Patch: 2.18.0 CWE-601 1.9K 5 ATLAS
MEDIUM

OpenClaw: symlink traversal exposes host filesystem

CVE-2026-43570
6.5
EPSS 0.1%
Supply Chain Data Extraction Agent Plugin
openclaw Patch: 2026.4.5 CWE-61 4 4 ATLAS 1 incident

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial