What changed in AI security, May 5 to May 11, 2025
May 5 to May 11, 2025 (ISO week 2025-W19). Weeks run Monday to Sunday in UTC.
13 records published, +5 on the previous week: 12 vulnerabilities (+7), 0 incidents (no change), 0 research items (no change), 1 news item (-1), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-7c85-87cp-mr6g: LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-1752GitHub Advisory Database - High
CVE-2025-0649: Tensorflow serving JSON input stringification flaw causes server crash
CVE-2025-0649NVD/CVE Database - High
CVE-2025-30165: vLLM unsafe pickle deserialization in multi-node ZeroMQ communication
CVE-2025-30165NVD/CVE Database - High
GHSA-pw95-88fg-3j6f: Langroid Allows XXE Injection via XMLToolMessage
CVE-2025-46726GitHub Advisory Database - Critical
CVE-2025-43852: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization in torch.load
CVE-2025-43852NVD/CVE Database - Critical
CVE-2025-43851: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization in torch.load
CVE-2025-43851NVD/CVE Database - Critical
CVE-2025-43850: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization via model path
CVE-2025-43850NVD/CVE Database - Critical
CVE-2025-43849: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization flaw
CVE-2025-43849NVD/CVE Database - Critical
CVE-2025-43848: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization via model path
CVE-2025-43848NVD/CVE Database - Critical
CVE-2025-43847: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization via model path
CVE-2025-43847NVD/CVE Database - Critical
CVE-2025-43846: Retrieval-based-Voice-Conversion-WebUI unsafe deserialization via model path
CVE-2025-43846NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.No research papers or reports were published in this week.
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.