ATLAS Landscape
AML.T0058

Publish Poisoned Models

Adversaries may publish a poisoned model to a public location such as a model registry or code repository. The poisoned model may be a novel model or a poisoned variant of an existing open-source model. This model may be introduced to a victim system via [AI Supply Chain Compromise](/techniques/AML.T0010).

Severity CVE CVSS
CRITICAL GHSA-vvpj-8cmc-gx39 10.0
CRITICAL CVE-2024-12029 9.8
CRITICAL CVE-2025-32434 9.8
CRITICAL CVE-2025-49655 9.8
CRITICAL GHSA-g38g-8gr9-h9xp 9.8
CRITICAL CVE-2026-22807 9.8
CRITICAL CVE-2020-13092 9.8
CRITICAL CVE-2025-1550 9.8
CRITICAL CVE-2025-54949 9.8
CRITICAL GHSA-ggpf-24jw-3fcw 9.8
CRITICAL CVE-2025-1945 9.8
CRITICAL CVE-2024-3568 9.6
CRITICAL CVE-2026-28500 9.1
HIGH CVE-2025-66448 8.8
HIGH GHSA-hgrh-qx5j-jfwx 8.8
HIGH CVE-2025-67729 8.8
HIGH CVE-2024-37059 8.8
HIGH CVE-2024-37058 8.8
HIGH CVE-2024-37057 8.8
HIGH CVE-2024-37056 8.8
HIGH CVE-2024-37055 8.8
HIGH CVE-2024-37054 8.8
HIGH CVE-2024-37053 8.8
HIGH CVE-2024-37052 8.8
HIGH CVE-2023-6730 8.8
HIGH CVE-2026-27893 8.8
HIGH CVE-2026-1462 8.8
HIGH CVE-2026-44513 8.8
HIGH GHSA-j7w6-vpvq-j3gm 8.8
HIGH CVE-2026-6859 8.8
HIGH CVE-2025-58756 8.8
HIGH CVE-2026-24747 8.8
HIGH CVE-2025-24357 8.8
HIGH CVE-2024-11394 8.8
HIGH CVE-2024-11393 8.8
HIGH CVE-2024-11392 8.8
HIGH CVE-2025-54886 8.4
HIGH CVE-2025-10157 8.3
HIGH CVE-2025-46567 7.8
HIGH CVE-2025-5173 7.8
HIGH CVE-2021-43811 7.8
HIGH CVE-2026-27905 7.8
HIGH CVE-2021-29589 7.8
HIGH CVE-2025-8747 7.8
HIGH CVE-2023-7018 7.8
HIGH CVE-2025-9905 7.3
HIGH CVE-2025-9906 7.3
MEDIUM CVE-2021-41213 5.5
MEDIUM CVE-2026-4538 5.3
LOW CVE-2020-26271 3.3
MEDIUM GHSA-r54c-2xmf-2cf3
MEDIUM GHSA-v7x6-rv5q-mhwc
MEDIUM GHSA-fj43-3qmq-673f
MEDIUM CVE-2025-1889
UNKNOWN CVE-2024-4897
UNKNOWN CVE-2026-27489
MEDIUM GHSA-3vg9-h568-4w9m
HIGH GHSA-97f8-7cmv-76j2
HIGH GHSA-5hwf-rc88-82xm
MEDIUM GHSA-mhc9-48gj-9gp3
HIGH GHSA-9m3x-qqw2-h32h
HIGH GHSA-46h3-79wf-xr6c
HIGH CVE-2026-22607
HIGH GHSA-955r-x9j8-7rhh
MEDIUM GHSA-6556-fwc2-fg2p
HIGH GHSA-rrxm-2pvv-m66x
MEDIUM GHSA-cffc-mxrf-mhh4
HIGH GHSA-3329-ghmp-jmv5
HIGH GHSA-x843-g5mx-g377
HIGH GHSA-vqmv-47xg-9wpr
UNKNOWN CVE-2025-14930
HIGH GHSA-r8g5-cgf2-4m4m
HIGH GHSA-m273-6v24-x4m4
UNKNOWN CVE-2025-14929
UNKNOWN CVE-2025-14928
UNKNOWN CVE-2025-14927
UNKNOWN CVE-2025-14926
UNKNOWN CVE-2025-14924
UNKNOWN CVE-2025-14921
UNKNOWN CVE-2025-14920
MEDIUM GHSA-q77w-mwjj-7mqx
MEDIUM GHSA-49gj-c84q-6qm9
MEDIUM GHSA-9w88-8rmg-7g2p
MEDIUM GHSA-fqq6-7vqf-w3fg
MEDIUM GHSA-3gf5-cxq9-w223
MEDIUM GHSA-j343-8v2j-ff7w
MEDIUM GHSA-m869-42cg-3xwr
MEDIUM GHSA-p9w7-82w4-7q8m
MEDIUM GHSA-xp4f-hrf8-rxw7
MEDIUM GHSA-4whj-rm5r-c2v8
MEDIUM GHSA-9xph-j2h6-g47v
MEDIUM GHSA-8r4j-24qv-fmq9
MEDIUM GHSA-cj3c-v495-4xqh
MEDIUM GHSA-7cq8-mj8x-j263
MEDIUM GHSA-6w4w-5w54-rjvr
MEDIUM GHSA-f54q-57x4-jg88
MEDIUM GHSA-6vqj-c2q5-j97w
MEDIUM GHSA-x696-vm39-cp64
MEDIUM GHSA-g344-hcph-8vgg
MEDIUM GHSA-5qwp-399c-mjwf
MEDIUM GHSA-vv6j-3g6g-2pvj
MEDIUM GHSA-vr7h-p6mm-wpmh
MEDIUM GHSA-h3qp-7fh3-f8h4
MEDIUM GHSA-f745-w6jp-hpxx
MEDIUM GHSA-86cj-95qr-2p4f
HIGH GHSA-9gvj-pp9x-gcfr