What changed in AI security, Nov 24 to Nov 30, 2025
Nov 24 to Nov 30, 2025 (ISO week 2025-W48). Weeks run Monday to Sunday in UTC.
15 records published, +2 on the previous week: 7 vulnerabilities (-6), 0 incidents (no change), 7 research items (+7), 1 news item (+1), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2025-66201: LibreChat server-side request forgery through Actions OpenAPI specs
CVE-2025-66201NVD/CVE Database - High
CVE-2025-12638: Keras path traversal in keras.utils.get_file() tar extraction
CVE-2025-12638NVD/CVE Database - Critical
CVE-2025-62593: Ray remote code execution via browser-based attacks using DNS rebinding
CVE-2025-62593NVD/CVE Database - High
CVE-2025-62703: Fugue remote code execution through pickle deserialization in FlaskRPCServer
CVE-2025-62703NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-62593: Ray remote code execution via browser-based attacks using DNS rebinding CVE-2025-62593NVD/CVE Database | Known exploited | 62.5% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| sdnq | PyPI | Hugging Face Hub / Transformers | 0.1.0 | |
| openenv-core | PyPI | FastMCP, Hugging Face Hub / Transformers, OpenAI SDK, smolagents | 0.1.1 | |
| memori | PyPI | FAISS | 3.0.0b1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.A Generative AI Application for Qualitative Automatic Population of Multimedia Knowledge Graphs
Peer-reviewedIEEE Xplore (Security & AI Journals)FedFlex: Protecting Shared Features in Vertical Federated Learning via Differential Privacy
Peer-reviewedIEEE Xplore (Security & AI Journals)Dual-Locking Learned AI Models: A PIN-Based Sparse QIM Watermarking and Adaptive Index Permutation Approach
Peer-reviewedIEEE Xplore (Security & AI Journals)Deep Learning With Data Privacy via Residual Perturbation
Peer-reviewedIEEE Xplore (Security & AI Journals)Adversarial Training in Low-Label Regimes With Margin-Based Interpolation
Peer-reviewedIEEE Xplore (Security & AI Journals)Investigating the Robustness of Fuzzy Deep Learning on Noisy Medical Images
Peer-reviewedIEEE Xplore (Security & AI Journals)2025-11-25
IndustryMCP Specification Releases
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.