AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
905 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
CVE-2024-27444
Remote Code Execution in LangChain via Unsanitized Shell Tool Input from LLM
langchain < 0.1.20
28 June 2026
2 views
Patched
CRITICAL
CVE-2026-28119
Remote Code Execution in LlamaIndex via Deserialization of Malicious Tool Output
Previous
Page 7 of 76
Next
LlamaIndex < 0.10.50
25 June 2026
0 views
Patched
CRITICAL
CVE-2026-35228
Cross-Tenant Data Exfiltration in Azure OpenAI Studio via WebSocket Manipulation
Azure OpenAI Studio
25 June 2026
1 views
Patched
CRITICAL
Credential Exfiltration via Malicious PyPI Package 'torch-optimizer' Targeting AI Developers
Python Package Index (PyPI)
25 June 2026
1 views
Patched
CRITICAL
Malicious PyPI Package 'torch-utils-nightly' Steals Cloud Credentials from AI Developer Environments
Python developer environments
CI/CD pipelines for ML projects
25 June 2026
1 views
Patched
HIGH
Malicious PyPI Package 'torch-utils-extra' Steals Hugging Face and AWS Credentials
Developers who installed the 'torch-utils-extra' PyPI package
25 June 2026
1 views
Patched
CRITICAL
CVE-2026-19842
NVIDIA Triton Inference Server Remote Code Execution via Malformed Model Configuration
NVIDIA Triton Inference Server < 2.65.0
25 June 2026
1 views
Patched
CRITICAL
Remote Code Execution via Deserialization of Maliciously Crafted Agent State in LangChain
LangChain < 0.3.5
25 June 2026
1 views
Patched
CRITICAL
Malicious Model on Hugging Face Hub Leads to Remote Code Execution via Unsafe Deserialization
PyTorch < 2.3
Hugging Face Hub (users downloading untrusted models)
25 June 2026
1 views
Unpatched
CRITICAL
Remote Code Execution via Malicious Pickle Deserialization in Community-Uploaded Hugging Face Models
PyTorch users
Hugging Face Transformers users
Any system loading .bin, .pkl, or .pth files from untrusted sources
25 June 2026
2 views
Unpatched
CRITICAL
Malicious Code Execution via Poisoned Hugging Face Model Weights Using Unsafe Deserialization
PyTorch < 2.1
Hugging Face Transformers (when loading models with `torch.load` from untrusted sources)
25 June 2026
6 views
Patched
CRITICAL
LangChain SQL Agent Vulnerable to Natural Language SQL Injection leading to Data Exfiltration
LangChain <0.1.20
langchain-community <0.0.30
25 June 2026
8 views
Patched