AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
932 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
CVE-2023-6958
MLflow Path Traversal Vulnerability Allows Arbitrary File Write and RCE
MLflow Server < 2.8.1
5 June 2025
1 views
Patched
MEDIUM
GitHub Copilot Suggests Verifiably Insecure Code and Leaks Secrets
Previous
Page 63 of 78
Next
GitHub Copilot
5 June 2025
11 views
Unpatched
CRITICAL
CVE-2023-4863
Heap Buffer Overflow in libwebp allows RCE in ML Container Images
NVIDIA NGC Containers (e.g., pytorch, tensorflow) prior to patch
Official TensorFlow and PyTorch Docker images
Any containerized ML workload using a vulnerable version of libwebp
3 June 2025
5 views
Patched
CRITICAL
CVE-2023-29374
Remote Code Execution in LangChain PALChain via Crafted Mathematical Prompts
langchain < 0.0.171
28 May 2025
13 views
Patched
CRITICAL
Remote Code Execution via Maliciously Crafted PyTorch Models on Hugging Face Hub
PyTorch
Hugging Face Transformers
Any system loading untrusted `.bin` or `.pkl` model files
20 May 2025
1 views
Unpatched
CRITICAL
CVE-2023-29374
Arbitrary Code Execution in LangChain via Unsandboxed Python REPL Tool
LangChain <0.0.171
20 May 2025
8 views
Patched
CRITICAL
Malicious PyPI Package `torch-optimizer` Steals Cloud Credentials from AI Developer Environments
PyPI Registry users
Python developers
20 May 2025
3 views
Patched
HIGH
Indirect Prompt Injection in GitHub Copilot Workspace via Malicious Markdown Files
GitHub Copilot (versions with workspace indexing prior to Q3 2025 patches)
Cursor IDE (all versions before 0.28.0)
20 May 2025
4 views
Patched
HIGH
Indirect Prompt Injection in AI Email Assistants via Third-Party Content Retrieval
AI Email Assistants
AI Agents with Web Browsing Tools
Retrieval-Augmented Generation (RAG) Systems
20 May 2025
6 views
Unpatched
CRITICAL
Remote Code Execution in LangChain ReAct Agent via Improperly Sanitized Tool Input
LangChain 0.1.x before 0.1.18
LangChain 0.2.x before 0.2.5
20 May 2025
5 views
Patched
CRITICAL
Malicious PyPI Package 'torch-inspector' Steals Cloud Credentials and SSH Keys
PyPI ecosystem
pip
20 May 2025
5 views
Patched
CRITICAL
CVE-2023-49080
Malicious PyPI Package 'torchtriton' Exfiltrates Sensitive Data from AI Development Environments
Python developers using PyPI
20 May 2025
5 views
Patched