What changed in AI security, Sep 22 to Sep 28, 2025
Sep 22 to Sep 28, 2025 (ISO week 2025-W39). Weeks run Monday to Sunday in UTC.
27 records published, +16 on the previous week: 22 vulnerabilities (+12), 0 incidents (no change), 3 research items (+2), 1 news item (+1), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-cr7q-2w66-hjcm: llama-index-core insecurely handles temporary files
CVE-2025-7647GitHub Advisory Database - High
CVE-2025-55560: PyTorch denial of service via to_sparse and to_dense compiled by Inductor
CVE-2025-55560NVD/CVE Database - High
CVE-2025-55559: TensorFlow denial of service when Conv2D padding is set to valid
CVE-2025-55559NVD/CVE Database - High
CVE-2025-55558: PyTorch buffer overflow in Inductor enables denial of service
CVE-2025-55558NVD/CVE Database - High
CVE-2025-55557: pytorch Name Error in Inductor causes denial of service
CVE-2025-55557NVD/CVE Database - High
CVE-2025-55553: PyTorch syntax error in proxy_tensor.py enables denial of service
CVE-2025-55553NVD/CVE Database - High
CVE-2025-55552: pytorch unexpected behavior with torch.rot90 and torch.randn_like
CVE-2025-55552NVD/CVE Database - High
CVE-2025-55551: pytorch torch.linalg.lu denial of service during slice operation
CVE-2025-55551NVD/CVE Database - Critical
CVE-2025-59828: Claude Code trust dialog bypass through Yarn plugin auto-execution
CVE-2025-59828NVD/CVE Database - High
CVE-2025-6921: huggingface/transformers ReDoS in AdamWeightDecay optimizer via regex patterns
CVE-2025-6921NVD/CVE Database - High
CVE-2025-59532: Codex CLI sandbox bypass allowing arbitrary file writes and command execution
CVE-2025-59532NVD/CVE Database - Critical
CVE-2025-59434: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025…
CVE-2025-59434NVD/CVE Database - Critical
CVE-2025-59528: Flowise remote code execution through CustomMCP node configuration
CVE-2025-59528NVD/CVE Database - High
CVE-2025-59527: Flowise server-side request forgery through /api/v1/fetch-links endpoint
CVE-2025-59527NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-59528: Flowise remote code execution through CustomMCP node configuration CVE-2025-59528NVD/CVE Database | Not listed | 86.2% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| claude-agent-sdk | PyPI | Claude Agent SDK | 0.0.23 | |
| @anthropic-ai/claude-agent-sdk | npm | Claude Agent SDK | 0.0.4 | |
| mcp-ui-server | PyPI | Model Context Protocol SDK | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 3 | 2.0 | +1.0 |
Research
Peer-reviewed first, then newest.ASGA: Attention-Based Sparse Global Attack to Video Action Recognition
Peer-reviewedIEEE Xplore (Security & AI Journals)Privacy-Preserving Automated Deep Learning for Secure Inference Service
Peer-reviewedIEEE Xplore (Security & AI Journals)Meet Trick With Trick: Revealing Collusion Intentions in Highly Concealed Poisoning Behavior
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.