AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 225 results — Critical severitycline: WebSocket auth bypass enables terminal RCE
CVE-2026-44211 Open WebUI has an LDAP Empty Password Authentication Bypass
CVE-2026-44551 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used...
CVE-2026-42208 vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
CVE-2026-44007 Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-44484 Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-42048 Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file...
CVE-2026-7482 Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
GHSA-wpqr-6v78-jr5g LiteLLM has SQL Injection in Proxy API key verification
GHSA-r75f-5x8p-qvmc Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass...
CVE-2026-41276 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated...
CVE-2026-41268 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)...
CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the...
CVE-2026-41265 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-41264 Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
GHSA-v38x-c887-992f OpenClaw: Feishu webhook and card-action validation now fail closed
GHSA-xh72-v6v9-mwhc Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
GHSA-9qhq-v63v-fv3j Flowise CSVAgent: RCE via Python code injection
GHSA-9wc7-mj3f-74xv Flowise: RCE via MCP stdio command injection
CVE-2026-40933 OpenAI Codex CLI: RCE via malicious MCP config files
CVE-2025-61260 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert