AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
CVE-2026-22417
GitHub Copilot Workspace Vulnerable to Container Escape via Malicious Markdown
GitHub Copilot Workspace (Private Beta)
20 Jan 2026
6 views
Patched
CRITICAL
CVE-2025-31090
Poisoned Model Weights on Hugging Face Hub Lead to Remote Code Execution
Previous
Page 32 of 41
Next
transformers 4.41.0 through 4.45.1
diffusers 0.25.0 through 0.27.2
2 Sept 2025
4 views
Patched
CRITICAL
Indirect Prompt Injection in LangChain ReAct Agents via Web Content Parsing
langchain 0.1.10 through 0.1.19
langchain-core 0.1.28 through 0.1.40
15 Apr 2025
4 views
Patched
CRITICAL
Arbitrary Code Execution via Malicious Model Weights using PyTorch's torch.load
PyTorch (all versions)
Hugging Face Transformers (when loading PyTorch models)
Any application using `torch.load` on untrusted model files
10 Mar 2026
4 views
Unpatched
CRITICAL
Cross-Tenant Data Exfiltration in Microsoft AI Studio via SSRF and Insecure Instance ID Handling
Microsoft Azure AI Studio
Microsoft Azure Machine Learning
29 Jan 2026
4 views
Patched
HIGH
Indirect Prompt Injection in Web-Browsing Agents Enables Account Takeover
LangChain agents with browsing tools
AutoGPT instances
LlamaIndex RAG pipelines using web readers
Custom AI agents with web access
5 Nov 2025
4 views
Unpatched
HIGH
Malicious PyPI Package 'torchtriton' Exfiltrates Sensitive Developer Data
Python developer environments
CI/CD pipelines for ML projects
20 June 2025
4 views
Unpatched
CRITICAL
CVE-2023-44467
Remote Code Execution in LangChain PALChain via Unsafe eval()
langchain <=0.0.314
15 Feb 2025
4 views
Patched
MEDIUM
Indirect Prompt Injection in AI Coding Assistants via Malicious Open-Source Code
GitHub Copilot
Cursor IDE
Amazon CodeWhisperer
28 Jan 2026
5 views
Unpatched
HIGH
CVE-2024-0074
NVIDIA GPU Driver Kernel Vulnerability Allows Container Escape
NVIDIA GPU Display Driver for Linux (versions before 550.40.07, 535.154.05, 525.147.05, 470.223.02)
19 Feb 2025
5 views
Patched
CRITICAL
Malicious PyPI Package `tensor-flow-nightly` Exfiltrates Cloud Credentials
PyPI package: tensor-flow-nightly (versions 2.18.0 to 2.18.3)
5 Nov 2025
6 views
Patched
CRITICAL
Privilege Escalation in AWS Bedrock Agents via Over-Privileged IAM Roles
AWS Bedrock Agents
GCP Vertex AI Agents
Azure OpenAI
22 Aug 2025
5 views
Unpatched