What changed in AI security, Oct 13 to Oct 19, 2025
Oct 13 to Oct 19, 2025 (ISO week 2025-W42). Weeks run Monday to Sunday in UTC.
15 records published, -4 on the previous week: 6 vulnerabilities (-6), 0 incidents (no change), 7 research items (no change), 1 news item (+1), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2025-49655: Keras deserialization flaw allows code execution via malicious files
CVE-2025-49655NVD/CVE Database - High
CVE-2025-62356: Qodo Gen IDE path traversal enables arbitrary local file read
CVE-2025-62356NVD/CVE Database - Critical
CVE-2025-62353: Windsurf IDE path traversal allowing arbitrary local file read and write
CVE-2025-62353NVD/CVE Database - High
GHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary File
CVE-2025-7707GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| langchain-baseten | PyPI | LangChain | 0.1.0 | |
| @langchain/classic | npm | LangChain | 1.0.0-alpha.1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Prompt injection and jailbreaks | 3 | 0.3 | +2.8 |
Research
Peer-reviewed first, then newest.Asynchronous Federated Learning With Nonconvex Client Objective Functions and Heterogeneous Dataset
Peer-reviewedIEEE Xplore (Security & AI Journals)A Mathematical Certification for Positivity Conditions in Neural Networks With Applications to Partial Monotonicity and Trustworthy AI
Peer-reviewedIEEE Xplore (Security & AI Journals)Really Unlearned? Verifying Machine Unlearning via Influential Sample Pairs
Peer-reviewedIEEE Xplore (Security & AI Journals)Do More With Less: Architecture-Agnostic and Data-Free Extraction Attack Against Tabular Model
Peer-reviewedIEEE Xplore (Security & AI Journals)Action-Perturbation Backdoor Attacks on Partially Observable Multiagent Systems
Peer-reviewedIEEE Xplore (Security & AI Journals)Engineering Trustworthy AI: A Developer Guide for Empirical Risk Minimization
Peer-reviewedIEEE Xplore (Security & AI Journals)v5.0.0
IndustryMITRE ATLAS Releases
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.