AI Component

Model

The model itself is an attack surface separate from the code that runs it. The model file is the first concern: pickle-based formats (PyTorch .bin, joblib, older HuggingFace) execute arbitrary code on load, so loading an untrusted model is loading untrusted code; safetensors solves this but adoption is incomplete. The model's behaviour is the second concern: adversarial examples bypass classifiers used as security controls, backdoor patterns planted during training survive deployment unless explicitly tested for, and model-extraction queries can clone proprietary fine-tunes. Production model registries (HuggingFace Hub, Ollama Library) have hosted backdoored variants of popular base models; HuggingFace now scans uploads for known-bad patterns, but defenses lag attacks. We track CVEs against model formats, model-loader libraries, and published research demonstrating new model-level attack classes against shipped commercial models.

255
Total CVEs
13
Pages
Page 5 of 13
Current
Severity CVE CVSS
MEDIUM CVE-2025-1474 5.5
CRITICAL CVE-2025-11200 9.8
HIGH CVE-2023-6730 8.8
HIGH CVE-2023-7018 7.8
CRITICAL CVE-2024-3568 9.6
HIGH CVE-2025-24357 8.8
HIGH CVE-2024-11392 8.8
HIGH CVE-2024-11393 8.8
HIGH CVE-2024-11394 8.8
MEDIUM CVE-2025-3264 5.3
HIGH CVE-2025-33213 8.8
UNKNOWN CVE-2025-14920 -
UNKNOWN CVE-2025-14921 -
UNKNOWN CVE-2025-14924 -
UNKNOWN CVE-2025-14926 -
UNKNOWN CVE-2025-14927 -
UNKNOWN CVE-2025-14928 -
UNKNOWN CVE-2025-14929 -
UNKNOWN CVE-2025-14930 -
HIGH CVE-2025-33233 7.8

Page 5 of 13