AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
932 vulnerabilities tracked — CVEs, prompt injection, model exploits.
CRITICAL
Remote Code Execution in LangChain via Maliciously Formatted Tool Output Parsing
langchain < 0.3.15
langchain-core < 0.2.10
12 Apr 2025
29 views
Patched
CRITICAL
CVE-2023-49080
Malicious `torchtriton` Package on PyPI Exfiltrates Sensitive Developer Data
Previous
Page 70 of 78
Next
Python developers using PyPI
11 Apr 2025
5 views
Patched
HIGH
Indirect Prompt Injection in Web-Browsing AI Agents Enables Data Exfiltration
LangChain agents using browsing tools
AutoGPT and similar autonomous agents
Custom-built AI applications with web retrieval
11 Apr 2025
22 views
Unpatched
HIGH
Data Exfiltration via Indirect Prompt Injection in LLM-Powered Recruitment Tools
LangChain ReAct Agents
LlamaIndex Agents
AutoGPT
Custom LLM-based applications with tool access
10 Apr 2025
3 views
Unpatched
HIGH
Indirect Prompt Injection in LLM-Powered Email Assistants Enables Data Exfiltration and Phishing
AI email assistants
Customer support chatbots
Web content summarization tools
Generic LLM-based agents
10 Apr 2025
9 views
Unpatched
HIGH
Cross-Tenant Data Leakage in Hugging Face Inference Endpoints via Shared GPU Memory
Hugging Face Inference Endpoints (shared infrastructure tiers)
10 Apr 2025
18 views
Patched
HIGH
CVE-2024-0091
NVIDIA CUDA Driver Kernel-Mode Flaw Allows Container Escape and Host Denial of Service
NVIDIA GPU Display Driver < 550.54.14 (Linux)
NVIDIA Studio Driver < 551.61 (Windows)
NVIDIA RTX Enterprise Driver < 537.99 (Windows)
10 Apr 2025
3 views
Patched
CRITICAL
Arbitrary Code Execution via Malicious Pickle Deserialization in Hugging Face Models
huggingface-hub <0.20.0
transformers <4.36.0
pickle
10 Apr 2025
10 views
Patched
CRITICAL
Malicious PyPI Package 'torchtriton' Steals Credentials from AI Developers
Python developers using PyPI
10 Apr 2025
12 views
Patched
HIGH
Self-Replicating GenAI Worm 'Morris II' Exfiltrates Data via Indirect Prompt Injection in Integrated Email Assistants
Conceptual attack targeting generative AI assistants
Microsoft 365 Copilot
Google Gemini Advanced
ChatGPT with browsing
5 Apr 2025
10 views
Unpatched
CRITICAL
Arbitrary Code Execution in Hugging Face Transformers Agent via Unsanitized LLM Output
transformers >= 4.29.0, < 4.30.0
5 Apr 2025
13 views
Patched
HIGH
CVE-2024-21390
Cross-Tenant Privilege Escalation in Azure AI Search Allows Unauthorized Data Access
Microsoft Azure AI Search
3 Apr 2025
12 views
Patched