What changed in AI security, Nov 3 to Nov 9, 2025
Nov 3 to Nov 9, 2025 (ISO week 2025-W45). Weeks run Monday to Sunday in UTC.
18 records published, +5 on the previous week: 14 vulnerabilities (+6), 0 incidents (no change), 3 research items (+1), 0 news items (-3), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2025-12488: oobabooga text-generation-webui remote code execution via trust_remote_code
CVE-2025-12488NVD/CVE Database - Critical
CVE-2025-12487: oobabooga text-generation-webui remote code execution through join endpoint
CVE-2025-12487NVD/CVE Database - High
CVE-2025-62039: Ays Pro AI ChatBot with ChatGPT and Content Generator sensitive data exposure
CVE-2025-62039NVD/CVE Database - High
GHSA-wwqv-p2pp-99h5: LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
CVE-2025-64439GitHub Advisory Database - High
CVE-2025-64110: Cursor logic bug lets agent read files protected by cursorignore
CVE-2025-64110NVD/CVE Database - High
CVE-2025-64108: Cursor NTFS path quirks allow file overwrite via prompt injection
CVE-2025-64108NVD/CVE Database - High
CVE-2025-64107: Cursor editor command execution via backslash path manipulation on Windows
CVE-2025-64107NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| universal-pathlib | PyPI | Hugging Face Hub / Transformers | 0.3.5 | |
| pytorch-lightning | PyPI | Hugging Face Hub / Transformers | 2.6.0.dev0 | |
| giskard-agents | PyPI | LiteLLM | 0.3.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.