Data Extraction
Data extraction attacks target the information processed or memorised by AI/ML systems. They take three main forms. First, training-data extraction: large language models can memorise verbatim spans of their training corpus, and an attacker who crafts the right prompts can pull back PII, API keys, or copyrighted text — a result demonstrated against GPT-2 by Carlini et al. and reproduced against several production models. Second, model extraction: by repeatedly querying a hosted model and observing outputs, an attacker can reconstruct enough behaviour to clone proprietary fine-tunes. Third, system-prompt and conversation leakage: indirect prompt injection or insecure logging can leak the application's instructions and other users' conversations. Multi-tenant inference platforms (vLLM, Triton, hosted APIs) and RAG systems are particularly exposed. Defenses: output filtering, differential privacy in training, rate limits, and strict tenant isolation.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| CRITICAL | CVE-2026-72811 | SiYuan: SQL injection enables cross-notebook DB access | 10.0 | |
| MEDIUM | CVE-2026-73560 | vLLM: SSRF/LFI bypass in MiMo-V2 multimodal input | vllm | 6.5 |
| CRITICAL | CVE-2026-64849 | MLflow: unauth SSRF via webhook hits cloud metadata | mlflow | 9.3 |
| HIGH | CVE-2026-35219 | Budibase: SSRF in automations reaches cloud metadata | - | |
| MEDIUM | CVE-2026-8810 | InsydeH2O: UEFI variable flaw exposes HDD password | InsydeH2O, InsydeH2O ARM | 6.9 |
| HIGH | CVE-2026-76254 | Splunk Enterprise: SPL injection via Dataset Explorer | 7.5 | |
| HIGH | CVE-2026-77071 | n8n: Supabase filter injection leaks/wipes full tables | n8n | - |
| HIGH | CVE-2026-72848 | LangChain: SitemapLoader SSRF bypasses domain restriction | langchain-community | 8.6 |
| HIGH | CVE-2026-55540 | PraisonAI: symlink escape defeats workspace path checks | PraisonAI | 7.1 |
| HIGH | CVE-2026-55526 | PraisonAI: SSRF bypass via DNS-rebinding hostname | praisonaiagents | 8.5 |
| HIGH | CVE-2026-55525 | PraisonAI: SSRF via redirect bypasses crawl allowlist | praisonaiagents | 7.5 |
| HIGH | CVE-2026-45019 | Chainlit: unauth SSRF via MCP url/header injection | chainlit | 7.2 |
Page 48 of 48