AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
926 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
CVE-2025-31589
Malicious Code Execution in Hugging Face Transformers via Poisoned Model Pickle Serialization
Hugging Face Transformers < 4.45.0
5 Sept 2025
26 views
Patched
HIGH
GitHub Copilot Context-Aware Prompt Injection Leads to Local File Exfiltration
Previous
Page 53 of 78
Next
GitHub Copilot VS Code Extension < 1.192.0
5 Sept 2025
32 views
Patched
CRITICAL
Cross-Tenant Data Exposure in Azure AI Services via SSRF in Managed Data Connectors
Azure AI Search (Preview)
Azure Machine Learning (Data Ingestion Connectors)
3 Sept 2025
3 views
Patched
CRITICAL
Malicious PyTorch Model on Hugging Face Hub Executes Code on Load via Unsafe Deserialization
transformers < 4.40.0
torch < 2.3.0
2 Sept 2025
12 views
Patched
CRITICAL
CVE-2025-31090
Poisoned Model Weights on Hugging Face Hub Lead to Remote Code Execution
transformers 4.41.0 through 4.45.1
diffusers 0.25.0 through 0.27.2
2 Sept 2025
9 views
Patched
CRITICAL
SSRF in AWS Bedrock Agent Allows IAM Credential Exfiltration
AWS Bedrock Agents (prior to service update on 2025-09-15)
2 Sept 2025
27 views
Patched
MEDIUM
ArtPrompt: Jailbreaking LLMs via ASCII Art Obfuscation
GPT-4o
Claude 3 Opus
Gemini 1.5 Pro
1 Sept 2025
0 views
Unpatched
CRITICAL
Malicious Model Execution on Hugging Face Hub via Unsafe Pickle Deserialization
Hugging Face Hub
PyTorch
TensorFlow
scikit-learn
22 Aug 2025
1 views
Unpatched
HIGH
Indirect Prompt Injection via Web Content Processing Leads to Agent Hijacking and Data Exfiltration
LangChain-based agents with browsing tools
LlamaIndex RAG pipelines
Custom AI agents with web browsing capabilities
AI-powered chatbots that summarize web pages
22 Aug 2025
5 views
Unpatched
HIGH
Malicious Code Execution via Trojanized TensorFlow Lite Models on Hugging Face Hub
TensorFlow Lite Runtime
Applications using TFLite models from untrusted sources
22 Aug 2025
5 views
Unpatched
CRITICAL
Malicious Model on Hugging Face Hub Leverages `pickle` Deserialization for Arbitrary Code Execution
Hugging Face Transformers
PyTorch
Any application loading models from untrusted sources via `pickle`
22 Aug 2025
11 views
Unpatched
CRITICAL
Privilege Escalation in AWS Bedrock Agents via Over-Privileged IAM Roles
AWS Bedrock Agents
GCP Vertex AI Agents
Azure OpenAI
22 Aug 2025
9 views
Unpatched