AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
932 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
CVE-2024-36603
Arbitrary Code Execution via Self-Correction Parser in LangChain Experimental Modules
langchain-experimental <= 0.0.58
20 May 2025
5 views
Patched
HIGH
Indirect Prompt Injection in LLM-Powered Assistants via Third-Party Data Parsing
Previous
Page 64 of 78
Next
Generic LLM Agent Architectures
LangChain Agents
OpenAI Assistants API
LlamaIndex Agents
20 May 2025
10 views
Unpatched
HIGH
CVE-2024-0081
Path Traversal in NVIDIA Triton Inference Server Allows Arbitrary File Read
NVIDIA Triton Inference Server < 24.01
20 May 2025
6 views
Patched
CRITICAL
Indirect Prompt Injection in LangChain ReAct Agent Allows Arbitrary Shell Command Execution
LangChain <0.1.0
All applications using LangChain agents with shell access tools
20 May 2025
11 views
Unpatched
HIGH
CVE-2024-0081
NVIDIA Triton Inference Server Path Traversal via Malicious Model Repository
NVIDIA Triton Inference Server <24.01
20 May 2025
23 views
Patched
CRITICAL
Arbitrary Code Execution via Malicious `pickle` Payload in Hugging Face Models
PyTorch < 2.1
Hugging Face Hub
TensorFlow < 2.13
20 May 2025
113 views
Patched
CRITICAL
Remote Code Execution via Maliciously Crafted Model on Hugging Face Hub
huggingface-hub
huggingface/transformers
torch
20 May 2025
7 views
Unpatched
CRITICAL
Malicious Code Execution via Poisoned Pickle-Serialized Models on Hugging Face Hub
PyTorch (all versions loading .pkl files)
Hugging Face Transformers (when loading untrusted models)
Any application using `pickle.load()` or `torch.load()` on untrusted model files
20 May 2025
62 views
Unpatched
HIGH
Sleeper Agent Attack: Trigger-based Backdoor in Fine-Tuned LLMs Enables Persistent Deceptive Behavior
Transformer-based Large Language Models
AI Model Hubs (e.g., Hugging Face Hub)
20 May 2025
12 views
Unpatched
HIGH
Indirect Prompt Injection in AI-Powered Email Assistants Leads to Data Exfiltration
Microsoft Copilot for 365
Google Duet AI for Workspace
Custom AI Agents with Web/Email Access
20 May 2025
13 views
Unpatched
HIGH
Data Exfiltration via Indirect Prompt Injection in AI Assistants Processing Third-Party Content
ChatGPT with browsing
LangChain Agents
Microsoft 365 Copilot
Various AI-powered browser extensions
20 May 2025
23 views
Unpatched
CRITICAL
CVE-2023-29374
Remote Code Execution in LangChain via Unsafe Python AST Evaluation in LLMMathChain
langchain <=0.0.149
15 May 2025
4 views
Patched