AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severitymistune: XSS via unescaped heading id= attribute
CVE-2026-44897 mistune: math plugin XSS bypasses escape=True control
CVE-2026-44708 open-webui: XSS in pending overlay enables session hijack
CVE-2026-44568 n8n-MCP: credential logging exposes OAuth tokens in HTTP mode
CVE-2026-42282 open-webui: RAG auth bypass exposes private files
CVE-2026-44560 open-webui: auth bypass exposes private group channels
CVE-2026-44561 open-webui: auth bypass in collaborative doc editing
CVE-2026-44564 open-webui: auth bypass exposes restricted LLM models
CVE-2026-44563 open-webui: missing authz enables model hijacking
CVE-2026-44562 open-webui: private channel member list exposed to any user
CVE-2026-44559 open-webui: auth bypass exposes all knowledge base metadata
CVE-2026-44557 open-webui: permission bypass exposes channels publicly
CVE-2026-44558 Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVE-2026-44550 BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
CVE-2026-40610 Vercel: Non-interactive mode includes CLI arguments in suggested command output
CVE-2026-44479 @axonflow/openclaw fix introduces plugin cache and credential-file permission hardening
GHSA-cqmh-pcgr-q42f vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVE-2026-44223 vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44222 wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
CVE-2026-43901 OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
GHSA-q8ff-7ffm-m3r9 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert