AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
926 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
AI Supply Chain Attack: Code Injection via Poisoned 'Sleeper Agent' Models
Hugging Face Hub Models
Custom Fine-Tuned LLMs
AI Coding Tools using public models
10 Sept 2025
27 views
Unpatched
CRITICAL
Hugging Face Inference Infrastructure Compromise via Malicious Model with `trust_remote_code=True`
Previous
Page 51 of 78
Next
Hugging Face Hub
Hugging Face Transformers < 4.45.0
AWS SageMaker
GCP Vertex AI
+1 more
8 Sept 2025
13 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in AI-Powered Email Assistants
Custom AI Agents
AI-powered Email Clients
Autonomous Web Browsing Agents
8 Sept 2025
3 views
Unpatched
CRITICAL
Malicious PyPI Package 'torchtriton' Steals Developer Credentials and SSH Keys
Python Package Index (PyPI)
8 Sept 2025
11 views
Patched
CRITICAL
PyPI Supply Chain Attack via Typosquatted 'torchtriton' Package Exfiltrates Sensitive Data
Python developers using PyPI
8 Sept 2025
15 views
Patched
HIGH
Indirect Prompt Injection in AI Agents via Compromised Data Sources
LangChain Agents
LlamaIndex Query Engines
AutoGPT
GitHub Copilot Workspace
+1 more
8 Sept 2025
12 views
Unpatched
HIGH
Indirect Prompt Injection in GitHub Copilot Chat Enables Corporate Data Exfiltration
GitHub Copilot for VS Code < 1.192.0
GitHub Copilot for JetBrains < 2.5.1
8 Sept 2025
5 views
Patched
CRITICAL
Command Injection in GitHub Copilot Workspace via Malicious Git Branch Names
GitHub Copilot Workspace (Beta builds from 2025-07-01 to 2025-09-04)
5 Sept 2025
0 views
Patched
MEDIUM
CVE-2025-10755
Denial of Service in NVIDIA CUDA Driver via Malformed Compute Kernels
NVIDIA Linux Driver 550.x < 550.78
NVIDIA Windows Driver 552.x < 552.61
5 Sept 2025
0 views
Patched
HIGH
Indirect Prompt Injection in AI Helpdesk via Unsanitized Web Content Leads to Privilege Escalation
Custom-built AI agents using RAG on untrusted web data
5 Sept 2025
0 views
Unpatched
CRITICAL
CVE-2025-6012
Insecure Deserialization in Ray Serve Leading to Remote Code Execution
Ray versions >= 2.0.0 and < 2.7.1
5 Sept 2025
0 views
Patched
HIGH
Indirect Prompt Injection in Microsoft Copilot Enabling Data Exfiltration
Microsoft Copilot (Web Interface)
Bing Chat Enterprise
5 Sept 2025
16 views
Patched