AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
Remote Code Execution in Hugging Face Hub via Malicious Pickled Models
PyTorch
TensorFlow
Hugging Face Transformers
Any application loading `.pkl` or `.pt` files from untrusted sources
21 July 2025
5 views
Patched
CRITICAL
Previous
Page 28 of 41
Next
Indirect Prompt Injection in LangChain ReAct Agents Leading to Arbitrary Code Execution
LangChain <0.1.0
AutoGPT
Other ReAct-based AI agents
12 Apr 2025
5 views
Unpatched
HIGH
CVE-2024-21390
Cross-Tenant Privilege Escalation in Azure AI Search Allows Unauthorized Data Access
Microsoft Azure AI Search
3 Apr 2025
7 views
Patched
CRITICAL
CVE-2024-21626
Container Breakout in ML Workloads via `runc` File Descriptor Leak Vulnerability
Docker Engine < 25.0.1
runc < 1.1.12
Kubernetes (all versions using a vulnerable runtime)
NVIDIA NGC Containers (published before Feb 2025)
+1 more
31 Jan 2025
5 views
Patched
HIGH
Indirect Prompt Injection in RAG Systems Enables Cross-Organizational Data Exfiltration
All RAG systems processing untrusted documents
LangChain Agents
LlamaIndex Agents
Custom AI Assistants with tool-use capabilities
10 Feb 2025
6 views
Unpatched
CRITICAL
Malicious Model on Hugging Face Hub Leverages `pickle` Deserialization for Arbitrary Code Execution
Hugging Face Transformers
PyTorch
Any application loading models from untrusted sources via `pickle`
22 Aug 2025
6 views
Unpatched
CRITICAL
Remote Code Execution in LangChain Agents via Unsanitized Shell Tool Input
LangChain < 0.2.5
15 May 2025
6 views
Patched
HIGH
GitHub Copilot Susceptible to 'Model Training Data Poisoning' for Malicious Code Injection
GitHub Copilot
OpenAI Codex
Other code generation models trained on public data
30 Nov 2025
17 views
Unpatched
HIGH
Indirect Prompt Injection in Microsoft Copilot Enables Conversation Hijacking and Data Exfiltration
Microsoft Copilot (Bing Chat)
22 Jan 2026
8 views
Patched
CRITICAL
PyPI Supply Chain Attack via Typosquatted 'torchtriton' Package Exfiltrates Sensitive Data
Python developers using PyPI
8 Sept 2025
6 views
Patched
HIGH
CVE-2024-0081
NVIDIA Triton Inference Server Path Traversal via Malicious Model Repository
NVIDIA Triton Inference Server <24.01
20 May 2025
12 views
Patched
CRITICAL
Remote Code Execution in LangChain via Manipulated Numerical Expressions in LLMMathChain
LangChain <0.1.0
15 Feb 2025
9 views
Patched