AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
926 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
Indirect Prompt Injection in Microsoft 365 Copilot via Malicious Email Payloads
Microsoft 365 Copilot
Azure OpenAI Service (in integrated applications)
Google Workspace Duet AI
22 July 2025
5 views
Unpatched
HIGH
Previous
Page 58 of 78
Next
Data Exfiltration via Poisoned Code Generation Model on Hugging Face Hub
Users of 'CodeWizard-Pro-7B' model (version 1.2) from Hugging Face Hub
22 July 2025
14 views
Unpatched
HIGH
Indirect Prompt Injection in LangChain ReAct Agents Allows Cross-User Data Exfiltration
LangChain 0.1.x
22 July 2025
5 views
Unpatched
CRITICAL
Remote Code Execution via Malicious 'pickle' Serialized Models on Hugging Face Hub
PyTorch <2.1
Hugging Face Transformers
Any application loading .pkl, .pt, or .bin files via pickle
22 July 2025
13 views
Unpatched
HIGH
Indirect Prompt Injection in AWS Bedrock via Malicious Document Processing Leads to IAM Role Compromise
AWS Bedrock
GCP Vertex AI
Azure OpenAI
22 July 2025
8 views
Unpatched
HIGH
Malicious Code Execution via Poisoned PyTorch Models on Hugging Face Hub
transformers>=4.0.0
torch<=2.4.0
Hugging Face Hub
22 July 2025
9 views
Unpatched
HIGH
CVE-2023-31037
Path Traversal in NVIDIA Triton Inference Server Enables Model and Data Tampering
NVIDIA Triton Inference Server < 23.08
22 July 2025
6 views
Patched
HIGH
Cross-Tenant Data Leakage in Multi-User RAG Applications via Misconfigured Azure AI Search Security Filters
Azure AI Search
Microsoft Semantic Kernel
LangChain (with Azure AI Search retriever)
22 July 2025
23 views
Unpatched
HIGH
CVE-2025-29812
SSRF in Azure OpenAI 'On Your Data' Feature Exposes Internal Network Services
Azure OpenAI Service ('On Your Data' feature)
22 July 2025
11 views
Patched
CRITICAL
Malicious PyPI Package 'torch-optimizer' Mimics Popular Library to Steal ML Model Weights and Cloud Credentials
Python developer environments
CI/CD pipelines for AI/ML projects
22 July 2025
10 views
Patched
CRITICAL
Malicious AI Model on Hugging Face Hub Leads to Supply Chain Compromise
Hugging Face Transformers
PyTorch
Any application loading models with `trust_remote_code=True`
22 July 2025
19 views
Unpatched
HIGH
Indirect Prompt Injection in Document-Aware AI Assistants Leading to Data Exfiltration
Custom RAG pipelines
LangChain applications using Retrieval-Augmented Generation
Azure OpenAI On Your Data
Amazon Bedrock Knowledge Bases
22 July 2025
10 views
Unpatched