AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
GitHub Copilot Workspace-Triggered Indirect Prompt Injection Enables Data Exfiltration
GitHub Copilot for VS Code < 1.190.0
Cursor IDE < 0.25.0
20 Jan 2026
2 views
Patched
CRITICAL
CVE-2024-0089
Heap Overflow in NVIDIA Triton Inference Server ONNX Runtime Backend Leads to Remote Code Execution
Previous
Page 34 of 41
Next
NVIDIA Triton Inference Server < 24.01
5 Sept 2025
6 views
Patched
CRITICAL
Malicious PyPI Package 'torch-optimizer' Mimics Popular Library to Steal ML Model Weights and Cloud Credentials
Python developer environments
CI/CD pipelines for AI/ML projects
22 July 2025
6 views
Patched
CRITICAL
Arbitrary Code Execution via Unsanitized Tool Input in LangChain ReAct Agents
LangChain < 0.2.0
15 Apr 2025
5 views
Patched
CRITICAL
Arbitrary Code Execution in Hugging Face Transformers Agent via Unsanitized LLM Output
transformers >= 4.29.0, < 4.30.0
5 Apr 2025
8 views
Patched
HIGH
CVE-2024-0091
NVIDIA GPU Driver Use-After-Free Vulnerability Allowing Denial of Service and Privilege Escalation
NVIDIA GPU Display Driver for Linux (versions prior to 550.40.07, 545.29.06, 535.154.05)
NVIDIA CUDA Toolkit (when bundled with vulnerable drivers)
22 Jan 2026
7 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in LLM-Powered Customer Support Tools
AI applications processing external data (emails, documents, web pages)
OpenAI GPTs with browsing/action capabilities
LangChain Agents
Customer support automation software using LLMs
10 June 2025
14 views
Unpatched
CRITICAL
Malicious Code Execution via Unsafe `pickle` Deserialization in Hugging Face Models
PyTorch
TensorFlow (via Keras .h5)
scikit-learn
Any application loading models from untrusted sources using pickle
20 Sept 2025
13 views
Unpatched
CRITICAL
CVE-2023-44467
Remote Code Execution in LangChain Experimental PALChain via Prompt-Induced `exec()`
langchain < 0.0.319
15 Feb 2025
1 views
Patched
HIGH
Data Exfiltration via Cross-Tenant Prompt Injection in AWS Bedrock-Powered Application
Custom multi-tenant applications using AWS Bedrock
Cloud AI services without strict context isolation
10 June 2025
12 views
Unpatched
CRITICAL
Malicious PyPI Package 'aigents' Steals Cloud Credentials from AI Developers
Python developers using PyPI
5 Nov 2025
18 views
Patched
HIGH
Indirect Prompt Injection in GitHub Copilot Leads to Vulnerable Code Suggestion
GitHub Copilot (all versions with context from open files)
29 Jan 2026
16 views
Unpatched