AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
Credential Theft via Malicious 'torchtriton' PyPI Typosquatting Package
Python developers using PyPI
CI/CD environments installing Python packages
15 Feb 2025
6 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in Markdown Image Rendering
Previous
Page 24 of 41
Next
AI agents processing external markdown content
ChatGPT with browsing capabilities
Custom LangChain/LlamaIndex agents with web retrieval tools
22 June 2025
6 views
Unpatched
HIGH
CVE-2023-31021
NVIDIA GPU Display Driver Kernel Mode Vulnerability Enables Privilege Escalation in AI Clusters
NVIDIA GPU Display Driver (Linux) < 535.129.03
NVIDIA GPU Display Driver (Linux) < 530.41.03
NVIDIA Studio Driver (Windows) < 546.01
20 July 2025
5 views
Patched
CRITICAL
Remote Code Execution via Insecure `pickle` Deserialization in Community-Uploaded Hugging Face Models
Hugging Face Transformers (when loading untrusted pickle-based models)
PyTorch (torch.load)
Any application loading `.pkl` or `.bin` model files from untrusted sources
28 Nov 2025
6 views
Patched
CRITICAL
Malicious Code Execution via Compromised `torch-optimizer` PyPI Package Targeting AI Developers
torch-optimizer 0.4.1
torch-optimizer 0.4.2
10 Jan 2026
5 views
Patched
HIGH
Self-Replicating GenAI Worm 'Morris II' Exfiltrates Data via Indirect Prompt Injection in Integrated Email Assistants
Conceptual attack targeting generative AI assistants
Microsoft 365 Copilot
Google Gemini Advanced
ChatGPT with browsing
5 Apr 2025
5 views
Unpatched
CRITICAL
CVE-2023-29374
Arbitrary Code Execution in LangChain via Unsafe Python `eval` in `LLMMathChain`
LangChain < 0.0.171
15 Feb 2025
9 views
Patched
CRITICAL
CVE-2023-36410
Cross-Tenant Credential Theft in Azure AI Machine Learning via SSRF
Azure AI Machine Learning Compute Instances
1 Aug 2025
4 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in RAG-Based AI Agents
LangChain-based RAG agents
LlamaIndex-based RAG agents
Custom AI assistants with web browsing capabilities
GitHub Copilot for PR summaries (when reading malicious files)
22 Jan 2026
9 views
Unpatched
HIGH
CVE-2024-0090
Privilege Escalation Vulnerability in NVIDIA GPU Display Driver for Linux
NVIDIA GPU Display Driver for Linux < 535.154.05
NVIDIA DGX Systems with affected drivers
Cloud instances (AWS, GCP, Azure) using vulnerable guest drivers
10 Nov 2025
5 views
Patched
CRITICAL
CVE-2023-29374
Remote Code Execution in LangChain via Unsafe Evaluation in LLMMathChain
LangChain < 0.0.171
15 Feb 2025
5 views
Patched
HIGH
CVE-2023-36410
SSRF Vulnerability in Azure OpenAI 'On Your Data' Feature Exposes Internal Services
Azure OpenAI Service
30 June 2025
7 views
Patched