What changed in AI security, Dec 1 to Dec 7, 2025
Dec 1 to Dec 7, 2025 (ISO week 2025-W49). Weeks run Monday to Sunday in UTC.
22 records published, +7 on the previous week: 12 vulnerabilities (+5), 0 incidents (no change), 6 research items (-1), 4 news items (+3), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2025-34291: Langflow account takeover and remote code execution via CORS and refresh token
CVE-2025-34291NVD/CVE Database - High
CVE-2025-33211: NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified…
CVE-2025-33211NVD/CVE Database - High
CVE-2025-33201: NVIDIA Triton Inference Server denial of service from oversized payloads
CVE-2025-33201NVD/CVE Database - Critical
CVE-2025-66032: Claude Code command injection via shell parsing of $IFS and short flags
CVE-2025-66032NVD/CVE Database - High
GHSA-9h52-p55h-vw2f: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-66416GitHub Advisory Database - High
GHSA-w48q-cv73-mx4w: Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
CVE-2025-66414GitHub Advisory Database - High
CVE-2025-66448: vLLM remote code execution through Nemotron_Nano_VL_Config auto_map entry
CVE-2025-66448NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-34291: Langflow account takeover and remote code execution via CORS and refresh token CVE-2025-34291NVD/CVE Database | Known exploited | 92.8% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @ag-ui/mcp-apps-middleware | npm | Model Context Protocol SDK | 0.0.1 | |
| tinker-cookbook | PyPI | Chroma, Google Gemini SDK, Hugging Face Hub / Transformers, LiteLLM, OpenAI SDK | 0.1.0 | |
| axolotl | PyPI | Hugging Face Hub / Transformers | 0.13.0.dev0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 3 | 0.5 | +2.5 |
Research
Peer-reviewed first, then newest.Learning Personalized Human Decision Models in Cyber Defense
Peer-reviewedIEEE Xplore (Security & AI Journals)User Isolation Poisoning on Decentralized Federated Learning: An Adversarial Message-Passing Graph Neural Network Approach
Peer-reviewedIEEE Xplore (Security & AI Journals)Frequency Bias Matters: Diving Into Robust and Generalized Deep Image Forgery Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Hello World
IndustryOpenAI Alignment Research BlogDebugging misaligned completions with sparse-autoencoder latent attribution
IndustryOpenAI Alignment Research BlogA Practical Approach to Verifying Code at Scale
IndustryOpenAI Alignment Research Blog
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.