What changed in AI security, May 25 to May 31, 2026
May 25 to May 31, 2026 (ISO week 2026-W22). Weeks run Monday to Sunday in UTC.
128 records published, -55 on the previous week: 32 vulnerabilities (-13), 0 incidents (no change), 11 research items (-8), 84 news items (-35), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-hvhp-v2gc-268q: PraisonAI has an Arbitrary File Write in Python API
CVE-2026-47397GitHub Advisory Database - Critical
GHSA-vg22-4gmj-prxw: PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVE-2026-47391GitHub Advisory Database - High
GHSA-9cr9-25q5-8prj: PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47394GitHub Advisory Database - Critical
GHSA-4mr5-g6f9-cfrh: PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVE-2026-47392GitHub Advisory Database - Critical
GHSA-8444-4fhq-fxpq: PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47393GitHub Advisory Database - High
GHSA-78r8-wwqv-r299: PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-47398GitHub Advisory Database - High
GHSA-c4m7-2gwp-vw76: ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env
CVE-2026-47211GitHub Advisory Database - High
CVE-2026-44285: FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability…
CVE-2026-44285NVD/CVE Database - High
GHSA-7j2f-6h2r-6cqc: Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
CVE-2026-47260GitHub Advisory Database - High
CVE-2026-46372: SillyTavern is a locally installed user interface that allows users to interact with text generation large language…
CVE-2026-46372NVD/CVE Database - Critical
CVE-2026-44650: SillyTavern is a locally installed user interface that allows users to interact with text generation large language…
CVE-2026-44650NVD/CVE Database - Critical
CVE-2026-44649: SillyTavern is a locally installed user interface that allows users to interact with text generation large language…
CVE-2026-44649NVD/CVE Database - High
CVE-2026-44648: SillyTavern is a locally installed user interface that allows users to interact with text generation large language…
CVE-2026-44648NVD/CVE Database - Critical
CVE-2026-45312: RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template…
CVE-2026-45312NVD/CVE Database - High
CVE-2026-4944: vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in…
CVE-2026-4944NVD/CVE Database - High
CVE-2026-45136: claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2…
CVE-2026-45136NVD/CVE Database - Critical
GHSA-mxfr-6hcw-j9rq: Langroid has Prompt to SQL Injection, Leading to RCE
CVE-2026-25879GitHub Advisory Database - High
CVE-2026-7528: IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
CVE-2026-7528NVD/CVE Database - Critical
CVE-2026-7524: IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links…
CVE-2026-7524NVD/CVE Database - Critical
CVE-2026-44895: GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts…
CVE-2026-44895NVD/CVE Database - High
CVE-2026-24162: NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of…
CVE-2026-24162NVD/CVE Database - High
GHSA-29pf-2h5f-8g72: HuggingFace transformers vulnerable to remote code execution
CVE-2026-4372GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| lfx-ibm | PyPI | LangChain | 0.1.0 | |
| use-computer | PyPI | Anthropic SDK, Google Gemini SDK, LiteLLM, OpenAI SDK | 0.0.28 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest. Showing 8 of 11.Model X-Ray: Detection of hidden malware in AI model weights using few shot learning
Peer-reviewedElsevier Security JournalsSurvey on Explainable AI for Traditional Machine Learning and Domains
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)PacketPatch: Practical generation and deployment of adversarial packets for byte-feature-based encrypted traffic classification
Peer-reviewedElsevier Security JournalsRobustness of Prompting: Enhancing Robustness of Large Language Models Against Prompt Attacks
Peer-reviewedIEEE Xplore (Security & AI Journals)EA-APO: A Universal Proactive Defense Against Facial Manipulation
Peer-reviewedIEEE Xplore (Security & AI Journals)Deformable 3-D Point Cloud Perturbations Using Cage-Based Deformation for Semantic Consistency
Peer-reviewedIEEE Xplore (Security & AI Journals)Federated Contrastive Diffusion Prototypes for Robust Private Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)<em>Infer-Shield</em>: Defending against membership inference attacks in heterogeneous federated learning via adaptive distillation
Peer-reviewedElsevier Security Journals
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.