AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
932 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
Arbitrary Code Execution via Maliciously Crafted Models on Hugging Face Hub
huggingface-hub (all versions)
transformers (all versions loading .bin files)
20 June 2025
12 views
Unpatched
HIGH
Malicious PyPI Package 'torchtriton' Exfiltrates Sensitive Developer Data
Previous
Page 62 of 78
Next
Python developer environments
CI/CD pipelines for ML projects
20 June 2025
9 views
Unpatched
HIGH
CVE-2023-25515
NVIDIA DCGM Integer Overflow Allows Privilege Escalation on GPU Nodes
NVIDIA DCGM versions prior to 3.1.8
NVIDIA DCGM versions prior to 2.4.14
NVIDIA DCGM versions prior to 2.3.10
20 June 2025
11 views
Patched
HIGH
GitHub Copilot 'Leaky Previews' Exposes Inter-Tenant Prompt and Completion Data
GitHub Copilot
18 June 2025
7 views
Patched
CRITICAL
Malicious Backdoor in Popular 'Mistral-7B-Instruct-v0.5' Fine-Tune on Hugging Face Hub
huggingface/some-popular-repo-mistral-7b-v0.5-finetune (revisions before 8a3d...)
transformers >= 4.30.0 with `trust_remote_code=True`
15 June 2025
24 views
Patched
HIGH
Indirect Prompt Injection in AI Email Assistants Enables Data Exfiltration
Various LLM-powered applications
AI Email Assistants
Web Browsing Agents
11 June 2025
4 views
Unpatched
HIGH
Malicious Code Execution via Backdoored Community-Contributed Quantized Models
huggingface-hub
transformers
auto-gptq
ctransformers
10 June 2025
9 views
Unpatched
CRITICAL
CVE-2024-21513
Remote Code Execution in LangChain Agents via Deserialization of Malicious Tool Outputs
LangChain < 0.2.5
10 June 2025
5 views
Patched
HIGH
CVE-2023-36867
GitHub Copilot for VS Code Suggests Hardcoded Secrets from Public Training Data
Visual Studio Code GitHub Copilot Extension <1.97.0
10 June 2025
5 views
Patched
HIGH
Data Exfiltration via Indirect Prompt Injection in LLM-Powered Customer Support Tools
AI applications processing external data (emails, documents, web pages)
OpenAI GPTs with browsing/action capabilities
LangChain Agents
Customer support automation software using LLMs
10 June 2025
18 views
Unpatched
HIGH
Data Exfiltration via Cross-Tenant Prompt Injection in AWS Bedrock-Powered Application
Custom multi-tenant applications using AWS Bedrock
Cloud AI services without strict context isolation
10 June 2025
16 views
Unpatched
CRITICAL
CVE-2023-34349
Malicious `torchtriton` Package on PyPI Steals Sensitive Data from AI/ML Systems
Python environments where `torchtriton` was installed
8 June 2025
3 views
Patched