AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
905 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
Indirect Prompt Injection in LangChain ReAct Agent via Malicious Markdown Documents
LangChain < 0.2.10
15 June 2026
6 views
Patched
HIGH
Arbitrary Code Execution in LangChain SQLDatabaseChain via Nested Query Injection
LangChain <0.2.5
Previous
Page 11 of 76
Next
15 June 2026
4 views
Patched
CRITICAL
CVE-2026-31337
Remote Code Execution in NVIDIA Triton Inference Server via Malicious ONNX Model
NVIDIA Triton Inference Server < 2.45.0
15 June 2026
6 views
Patched
HIGH
Cross-Tenant Inference Side-Channel Attack in AWS Bedrock Provisioned Concurrency
AWS Bedrock Provisioned Concurrency
15 June 2026
6 views
Patched
CRITICAL
CVE-2026-28419
Remote Code Execution in LangChain via Unsafe Deserialization in `YamlConfigParser` Tool
langchain-experimental >= 0.0.60, < 0.0.65
15 June 2026
6 views
Patched
CRITICAL
CVE-2026-19841
Remote Code Execution in LangChain SQL Agent via Unsanitized Natural Language Input
langchain>=0.1.15, <0.1.20
langchain-community>=0.0.32, <0.0.38
15 June 2026
4 views
Patched
CRITICAL
CVE-2026-28113
Malicious PyPI Package 'huggingface-tranformers' Steals Cloud Credentials
Python developer environments
15 June 2026
6 views
Patched
HIGH
CVE-2026-29375
Remote Code Execution in LangChain's LLMMathChain via Unsanitized Prompt Input
LangChain <0.2.5
15 June 2026
10 views
Patched
CRITICAL
CVE-2026-28104
Indirect Prompt Injection in LangChain SQLDatabaseChain leading to SQL Injection
langchain < 0.2.15
15 June 2026
7 views
Patched
CRITICAL
Remote Code Execution in LangChain via Unsanitized Markdown Code Block Parsing in Custom Tools
LangChain applications with custom shell execution tools
15 June 2026
12 views
Unpatched
CRITICAL
Cross-Tenant Data Exfiltration in Azure AI Studio via Inference API Cache Poisoning
Azure AI Studio Managed Endpoints (before May 2026 platform update)
15 June 2026
10 views
Patched
CRITICAL
CVE-2026-31011
Malicious Model on Hugging Face Hub Executes Remote Code via Pickled Payload
PyTorch < 2.3.0
Hugging Face Transformers < 4.41.0
Any application loading `.bin` or `.pkl` models via `torch.load()`
15 June 2026
11 views
Patched