AI Component

Model

The model itself is an attack surface separate from the code that runs it. The model file is the first concern: pickle-based formats (PyTorch .bin, joblib, older HuggingFace) execute arbitrary code on load, so loading an untrusted model is loading untrusted code; safetensors solves this but adoption is incomplete. The model's behaviour is the second concern: adversarial examples bypass classifiers used as security controls, backdoor patterns planted during training survive deployment unless explicitly tested for, and model-extraction queries can clone proprietary fine-tunes. Production model registries (HuggingFace Hub, Ollama Library) have hosted backdoored variants of popular base models; HuggingFace now scans uploads for known-bad patterns, but defenses lag attacks. We track CVEs against model formats, model-loader libraries, and published research demonstrating new model-level attack classes against shipped commercial models.

255
Total CVEs
13
Pages
Page 3 of 13
Current
Severity CVE CVSS
MEDIUM CVE-2022-23589 6.5
HIGH CVE-2022-23590 7.5
HIGH CVE-2022-23591 7.5
MEDIUM CVE-2022-23594 5.5
MEDIUM CVE-2022-29212 5.5
CRITICAL CVE-2023-5245 9.8
CRITICAL CVE-2024-3660 9.8
HIGH CVE-2024-37057 8.8
MEDIUM CVE-2025-12343 5.5
HIGH CVE-2021-43811 7.8
CRITICAL CVE-2023-43654 9.8
MEDIUM CVE-2024-31584 5.5
HIGH CVE-2024-37059 8.8
MEDIUM CVE-2025-1944 6.5
CRITICAL CVE-2025-1945 9.8
LOW CVE-2025-2149 2.5
MEDIUM CVE-2025-2953 5.5
CRITICAL CVE-2025-32434 9.8
HIGH CVE-2025-10155 7.8
MEDIUM CVE-2025-46150 5.3

Page 3 of 13