AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
483 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
CVE-2024-27444
Arbitrary Code Execution in LangChain's LLMMathChain via Crafted Prompt
langchain <0.1.9
15 Feb 2025
0 views
Patched
MEDIUM
GitHub Copilot Markdown Injection Enables Silent Data Exfiltration from VS Code
Previous
Page 2 of 41
Next
GitHub Copilot for VS Code < 1.185.0
30 June 2025
0 views
Patched
HIGH
Cross-Tenant Secret Exfiltration in Hugging Face Hub via Insecure CI/CD Action Configuration
Hugging Face Hub
20 Jan 2026
0 views
Patched
HIGH
CVE-2024-0081
Path Traversal in NVIDIA Triton Inference Server Allows Model Overwrite
NVIDIA Triton Inference Server < 25.10
10 Nov 2025
0 views
Patched
MEDIUM
GitHub Copilot Context Mixing Exposes Sensitive Information Across Files
GitHub Copilot for VS Code < 1.151.0
GitHub Copilot for JetBrains < 1.4.1
11 Mar 2026
0 views
Patched
HIGH
CVE-2024-0073
NVIDIA GPU Driver Vulnerability Allows Denial-of-Service in Multi-Tenant AI Environments
NVIDIA GPU Display Driver for Linux < 535.161.07
NVIDIA GPU Display Driver for Windows < 551.61
NVIDIA Tesla Driver for Linux < 535.161.07
18 Feb 2026
0 views
Patched
HIGH
Indirect Prompt Injection in Microsoft Copilot Enabling Data Exfiltration
Microsoft Copilot (Web Interface)
Bing Chat Enterprise
5 Sept 2025
0 views
Patched
CRITICAL
CVE-2023-36258
Remote Code Execution via Unsafe Python `eval` in LangChain's `PALChain`
LangChain < 0.0.171
9 July 2025
0 views
Patched
MEDIUM
GitHub Copilot Suggests Insecure Deserialization Patterns in Java Applications
GitHub Copilot (All versions)
18 Feb 2026
0 views
Unpatched
HIGH
CVE-2024-0082
Path Traversal in NVIDIA Triton Inference Server Enables Arbitrary File Access
NVIDIA Triton Inference Server < 24.01
30 Jan 2025
0 views
Patched
HIGH
Indirect Prompt Injection in LangChain Agent Enables Exfiltration of Sensitive Data
LangChain 0.1.x
LlamaIndex 0.9.x
Any AI agent system that parses and reasons over untrusted external data
21 Sept 2025
0 views
Unpatched
CRITICAL
Malicious Model Weights on Hugging Face Hub Leading to Remote Code Execution
Any system loading PyTorch models via `torch.load`
Any system loading models with `pickle.load`
Hugging Face Hub (as a distribution platform)
12 Apr 2025
0 views
Unpatched