What changed in AI security, Jul 14 to Jul 20, 2025
Jul 14 to Jul 20, 2025 (ISO week 2025-W29). Weeks run Monday to Sunday in UTC.
11 records published, -3 on the previous week: 8 vulnerabilities (-4), 0 incidents (no change), 1 research item (no change), 1 news item (no change), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2025-49747: Azure Machine Learning missing authorization allows privilege elevation
CVE-2025-49747NVD/CVE Database - Critical
CVE-2025-49746: Azure Machine Learning improper authorization allows privilege elevation
CVE-2025-49746NVD/CVE Database - Critical
CVE-2025-49841: GPT-SoVITS-WebUI unsafe deserialization in process_ckpt.py
CVE-2025-49841NVD/CVE Database - Critical
CVE-2025-49840: GPT-SoVITS-WebUI unsafe deserialization in change_gpt_weights via GPT_dropdown
CVE-2025-49840NVD/CVE Database - Critical
CVE-2025-49839: GPT-SoVITS-WebUI unsafe deserialization of model path in bsroformer.py
CVE-2025-49839NVD/CVE Database - Critical
CVE-2025-49838: GPT-SoVITS-WebUI unsafe deserialization in AudioPreDeEcho model loading
CVE-2025-49838NVD/CVE Database - Critical
CVE-2025-49837: GPT-SoVITS-WebUI unsafe deserialization in AudioPre model loading
CVE-2025-49837NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @brave/brave-search-mcp-server | npm | Model Context Protocol SDK | 1.3.1 | |
| any-llm-sdk | PyPI | Anthropic SDK, Azure AI Inference / Azure OpenAI SDK, Cohere SDK, Google Gemini SDK, Groq SDK, Hugging Face Hub / Transformers, Mistral AI SDK, Ollama client, OpenAI SDK, Together AI SDK, xAI SDK | 0.0.1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.