Solution sectors / ai-ml
AI & ML
The AI/ML stack — LLM serving and inference engines, ML frameworks, vector databases and agent tooling — is evolving fast and increasingly exposed to the internet. This hub tracks its emerging CVEs.
Cumulative CVEs
4,401
across 119 monthly snapshots
Latest month
180 · proj
-35.3% MoM · +127.8% YoY
Peak month
315
Mar 25
KEV this month
0
37 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- SaaS81%
- Mixed13%
- Library6%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to AI & ML.
- CVE-2026-91201DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage5.4
- CVE-2026-90818netease-youdao LobsterAI Browser Network Configuration openclawConfigSync.ts OpenClawConfigSync.buildBrowserConfig server-side request forgery4.3
- CVE-2026-55253LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure7.7
- CVE-2026-55235langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication5.9
- CVE-2026-55236langgraph-api: Incomplete assistant authorization in LangGraph Server run creation5.9
- CVE-2026-57145PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation9.1
- CVE-2026-57132PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication8.2
- CVE-2026-57131praisonai: Jobs API exposes agent-execution endpoints with no authentication9.8
- CVE-2026-57124PraisonAI UI MCP connect endpoint allows unauthenticated local command execution9.8
- CVE-2026-57122PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)8.6
- CVE-2026-57127praisonai: recipe serve auth middleware silently disables itself when no secret is set9.8
- CVE-2026-56839PraisonAI Code agent tools fail open without a workspace boundary7.3
- CVE-2026-57119PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API7.5
- CVE-2026-57129PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal7.5
- CVE-2026-57126praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS8.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| open-webui | 18 | · | · |
| langflow | 17 | · | · |
| nousresearch | 7 | · | · |
| flowiseai | 4 | · | · |
| openai | 4 | 1 | · |
| ggml | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| ai-agent-tooling | 55 | 1 | · | 11 | — | open-webui (18) · langflow (17) · hermes-agent (7) |
| llm-serving-inference | 21 | 4 | · | 13 | — | codex desktop (4) · codex desktop (microsoft store package) (4) · llama.cpp (4) |
| ml-framework | 10 | 2 | · | 9 | — | azure ai language authoring (1) · fedml (1) · llamafactory (1) |
| notebook-mlops | 4 | 1 | · | 4 | — | aim (1) · mlflow (1) · nbviewer (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification