aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9705 items

CVE-2026-45401: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the v

highvulnerability
security
May 15, 2026
CVE-2026-45401

Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.5 where it only checked the first URL a user submitted but didn't check where that URL redirected to (HTTP redirects are automatic forwards to different addresses). This meant authenticated users could trick the system into accessing internal addresses like 127.0.0.1 or 169.254.169.254 (special private IP addresses) and read sensitive data from those internal systems.

Fix: This vulnerability is fixed in 0.9.5.

NVD/CVE Database

ArXiv will ban researchers who upload papers full of AI slop

infonews
policy
May 15, 2026

ArXiv, a platform where researchers share academic papers before formal publication, is implementing new rules to reduce AI slop (low-quality or unreliable AI-generated content). Authors who submit papers with clear evidence they didn't check their AI outputs, such as hallucinated references (false citations made up by the AI) or leftover comments from an LLM (large language model, an AI trained on massive amounts of text), will be banned from the platform for one year and must have future papers accepted at a reputable peer-reviewed venue.

CVE-2026-44563: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /

mediumvulnerability
security
May 15, 2026
CVE-2026-44563

Open WebUI, a self-hosted AI platform that runs offline, had a vulnerability before version 0.9.0 where certain API endpoints (like /api/generate and /api/embeddings) accepted any model name from users and sent requests to the backend without checking if those users had permission to use that model. The endpoints only verified that a user was logged in and that the model existed, but skipped the access control check (AccessGrants.has_access(), which determines what resources a user is allowed to access).

CVE-2026-44556: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /

highvulnerability
security
May 15, 2026
CVE-2026-44556

Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.0 where the /responses endpoint allowed any logged-in user to access any model on the system without proper permission checks. While the main chat endpoint verified that users had the right to use specific models through ownership, group membership, and access grants, the /responses proxy skipped these checks and only confirmed the user was logged in, letting attackers use models they shouldn't have access to.

GHSA-c3ch-22rq-xfwr: AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`

mediumvulnerability
security
May 15, 2026
CVE-2026-45619

A previous security fix for CVE-2026-43884 in AVideo was incomplete. The fix patched two files to use a safer URL function, but six or more other parts of the code still don't properly use the `$resolvedIP` parameter (a value returned by the safety check that locks in which server to connect to), leaving the application vulnerable to DNS-rebinding TOCTOU attacks (time-of-check-time-of-use exploits where an attacker changes which IP address a domain points to between when the code checks it and when it actually connects).

GHSA-xw67-cg5f-4m2r: AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

highvulnerability
security
May 15, 2026
CVE-2026-45578

AVideo has a command injection vulnerability in `plugin/Live/on_publish.php` where user-controlled stream keys are inserted into a shell command using literal single quotes instead of proper escaping. An attacker can break out of the quotes by including a single quote character in the stream key, allowing them to inject and execute arbitrary shell commands on the server.

OpenAI keeps shuffling its executives in bid to win AI agent battle

infonews
industry
May 15, 2026

OpenAI reorganized its leadership structure to focus on developing AI agents (AI systems that can independently perform multiple tasks and make decisions). The company plans to merge ChatGPT and Codex (a code-generation AI tool) into a single unified platform designed around this agentic approach, with president Greg Brockman now overseeing all product decisions.

Laconic attribute-based PSI on authenticated inputs and applications

inforesearchPeer-Reviewed
security

Hardening Memory-Safe Languages: An Empirical Study of Attack Mitigations in Rust and Go Binaries

inforesearchPeer-Reviewed
security

GHSA-rpj4-7x2v-wjrf: Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

highvulnerability
security
May 15, 2026
CVE-2026-45548

Budibase's AI Extract File automation step has a server-side request forgery vulnerability (SSRF, a type of attack where a server makes requests to internal addresses it shouldn't access) because it uses `fetch()` directly without IP blacklist validation. Every other automation step in the same codebase properly uses `fetchWithBlacklist()` to block requests to internal networks like 127.0.0.1 and 169.254.169.254, but the AI step bypasses these protections, allowing authenticated users to access cloud metadata, scan internal networks, and potentially steal credentials.

The AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phases

infonews
securitypolicy

CVE-2026-46383: Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta

mediumvulnerability
security
May 15, 2026
CVE-2026-46383

Microsoft APM is a tool that manages dependencies for AI agents, and versions before 0.13.0 have a security flaw on Windows systems. When installing a bundle (a package of code) from a .tar.gz file (a compressed archive format), the tool extracts files without properly checking if any file paths could escape the intended folder, potentially allowing an attacker to place files anywhere on the system by using absolute paths like D:/.

CVE-2026-45539: Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive

highvulnerability
security
May 15, 2026
CVE-2026-45539

Microsoft APM, a dependency manager for AI agents, had a vulnerability in versions 0.5.4 to 0.12.4 where symbolic links (shortcuts that point to other files) in downloaded packages were followed without checking, potentially allowing attackers to read or write arbitrary files on a developer's machine. The vulnerability went undetected by security checks because the resulting files were not flagged by the package hash verification, security scans, or audit tools.

CVE-2026-44641: Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma

highvulnerability
security
May 15, 2026
CVE-2026-44641

Microsoft APM is a tool that manages dependencies (external code libraries) for AI agents. Before version 0.8.12, it had a path traversal vulnerability (a security flaw where an attacker can access files outside the intended directory) that allowed malicious plugins to copy arbitrary files from a user's computer during installation by using absolute paths or '../' sequences to escape the plugin directory.

AI radio hosts demonstrate why AI can’t be trusted alone

infonews
safety
May 15, 2026

Andon Labs ran an experiment where four different AI models (Claude, ChatGPT, Gemini, and Grok) were each given $20 to run their own radio station independently, with instructions to develop a personality and make a profit. All of them failed quickly, burning through their initial funding, demonstrating that AI systems cannot be reliably trusted to operate businesses or make sound decisions without human oversight.

GHSA-3363-2ph6-35wh: Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

highvulnerability
security
May 15, 2026
CVE-2026-44716

Pipecat's development runner has a path traversal vulnerability (a flaw that lets attackers access files outside the intended directory) in its `/files` endpoint. An attacker can use URL-encoded slashes (`%2F` instead of `/`) to bypass Starlette's (the web framework) security checks and read any file accessible to the Pipecat process, such as SSH keys or system files, without needing credentials.

Google updates its spam rules to include attempts to ‘manipulate’ AI

infonews
securitypolicy

OpenAI now wants ChatGPT to access your bank accounts

infonews
securityprivacy

In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

infonews
securitypolicy

Toward Secure and Efficient Driver Support for Embedded TEE Systems

inforesearchPeer-Reviewed
security
Previous226 / 486Next

Fix: According to ArXiv's Code of Conduct, authors must not submit papers with incontrovertible evidence that they failed to review LLM-generated results. Those found in violation face a one-year ban from ArXiv and must have subsequent submissions accepted at a reputable peer-reviewed venue before resubmission.

The Verge (AI)

Fix: The vulnerability is fixed in version 0.9.0.

NVD/CVE Database

Fix: This vulnerability is fixed in 0.9.0.

NVD/CVE Database

Fix: The source text references a correct implementation pattern in `plugin/YPTWallet/YPTWallet.php:1071-1098` that shows how to properly use the `$resolvedIP` out-param with `curl_setopt($ch, CURLOPT_RESOLVE, ...)` for DNS pinning. However, the source does not explicitly state what developers should do to fix the six+ vulnerable call sites.

GitHub Advisory Database
GitHub Advisory Database
The Verge (AI)
May 15, 2026

This academic paper, published in July 2026, presents research on laconic attribute-based PSI (private set intersection, a technique that lets two parties find common items in their datasets without revealing the full datasets to each other) applied to authenticated inputs. The work appears to focus on theoretical cryptographic methods for secure data comparison while maintaining privacy and verifying that the data being compared is legitimate.

Elsevier Security Journals
May 15, 2026

This research paper examines how well attack mitigations (security protections built into code) actually work in Rust and Go, two programming languages designed to be memory-safe (meaning they prevent common memory-related bugs that attackers often exploit). The study analyzes real compiled programs to see whether these language protections hold up against real-world attacks.

Elsevier Security Journals
GitHub Advisory Database
May 15, 2026

The AWS AI Security Framework is a structured approach that helps organizations secure AI systems by applying the right security controls across three layers (infrastructure, identity/data, and AI application), three use cases (question-answering AI, data-connected AI like RAG, and autonomous agents), and three phases (prototype, production, and scale). The framework addresses unique AI security challenges like prompt injection (tricking AI systems by hiding malicious instructions in user input) and non-deterministic outputs by implementing input validation, content filtering, and continuous monitoring from day one of development.

Fix: The framework recommends implementing controls across three phases: Phase 1 (Foundational) involves extending existing controls to AI, establishing identity management and fine-grained access controls, and adding content filtering and guardrails; Phase 2 (Enhanced) adds threat detection, data classification, and AI-specific monitoring for production; Phase 3 (Advanced) automates governance, compliance, and incident response at scale. AWS also offers a no-cost SHIP engagement to baseline security posture and build a prioritized roadmap.

AWS Security Blog

Fix: This vulnerability is fixed in version 0.13.0.

NVD/CVE Database

Fix: This vulnerability is fixed in version 0.13.0.

NVD/CVE Database

Fix: This vulnerability is fixed in version 0.8.12. Users should update Microsoft APM to 0.8.12 or later.

NVD/CVE Database
The Verge (AI)
GitHub Advisory Database
May 15, 2026

Google updated its spam policy to classify attempts to manipulate its AI search results as spam, including tactics like biased listicles or recommendation poisoning (injecting false information to trick an LLM into giving preferred answers). This rule applies to Google Search's AI features like AI Overview and AI Mode.

The Verge (AI)
May 15, 2026

OpenAI announced a new preview feature that will let ChatGPT connect directly to users' bank accounts through Plaid, a platform that links banking apps to third-party services. This integration would give the chatbot access to detailed financial information, including credit card debt and account balances, to help answer users' finance questions.

The Verge (AI)
May 15, 2026

This cybersecurity news roundup covers several significant incidents and developments, including a data breach at Nvidia's GeForce NOW service in Armenia that exposed user personal information, extended security update timelines for foreign-made routers and drones, and OpenAI's offer to give EU regulators access to a specialized version of GPT-5.5 for monitoring cyber security risks. The roundup also highlights an active malware campaign targeting developers with fake Claude Code installers, an Iran-linked group breaching South Korean electronics manufacturers, and Google's Android 17 release introducing AI-driven security features like verified financial calls and real-time threat detection.

Fix: For the fake Claude Code installer campaign, the source explicitly mentions the discovery but does not provide a stated mitigation. For Android 17, the source describes the security upgrades included in the update itself (verified financial calls, Live Threat Detection, post-quantum cryptography, automatic OTP hiding, and default-on theft protections), which function as built-in protections rather than external mitigations. For the FCC router waiver, the solution is the extended update window allowing security patches and firmware updates until at least January 1, 2029. No other explicit mitigations or patches are discussed in the source for the remaining incidents.

SecurityWeek
May 15, 2026

This paper addresses the problem that trusted execution environments (TEEs, like TrustZone, which are isolated secure areas in processors that protect sensitive data from untrusted software) typically have poor support for device drivers. The researchers propose a "twin driver" approach where matching drivers run in both the TEE and the untrusted operating system, supported by analysis tools and a sandbox environment that keeps the TEE minimal and secure while allowing efficient driver operation.

IEEE Xplore (Security & AI Journals)