What changed in AI security, Dec 15 to Dec 21, 2025
Dec 15 to Dec 21, 2025 (ISO week 2025-W51). Weeks run Monday to Sunday in UTC.
14 records published, -15 on the previous week: 5 vulnerabilities (-6), 0 incidents (no change), 7 research items (-11), 1 news item (+1), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2025-68478: Langflow arbitrary file write through the fs_path request field
CVE-2025-68478NVD/CVE Database - High
CVE-2025-68477: Langflow server-side request forgery through the API Request component
CVE-2025-68477NVD/CVE Database - Critical
CVE-2025-63389: Ollama API endpoints missing authentication enable unauthorized model management
CVE-2025-63389NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| opentelemetry-instrumentation-vertexai | PyPI | Google Vertex AI SDK | 2.2b0 | |
| paper-qa-nemotron | PyPI | LiteLLM | 2025.12.17 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.Inner-Probe: Discovering Copyright-Related Data Generation in LLM Architecture
Peer-reviewedIEEE Xplore (Security & AI Journals)The Most Overestimated Q Value Regularization in High-Dimensional Discrete Action Spaces for Offline Reinforcement Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Model Steganography During Model Compression
Peer-reviewedIEEE Xplore (Security & AI Journals)Trap: Mitigating Poisoning-Based Backdoor Attacks by Treating Poison With Poison
Peer-reviewedIEEE Xplore (Security & AI Journals)Dynamic Attention Analysis for Backdoor Detection in Text-to-Image Diffusion Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Evolving AI Transparency: The Journey of the AIBOM Generator and Its New Home at OWASP
IndustryOWASP GenAI SecuritySidestepping Evaluation Awareness and Anticipating Misalignment with Production Evaluations
IndustryOpenAI Alignment Research Blog
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.