Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
84 items
It’s official: The Pentagon has labeled Anthropic a supply-chain risk
Mar 5, 2026InfoNewsPolicyIndustryThe Department of Defense has notified Anthropic leadership that the company and its products are designated a supply-chain risk, according to Bloomberg, after weeks of conflict over military use of Anthropic's AI systems. The designation requires any company or agency working with the Pentagon to certify that it does not use Anthropic's models, a move critics call unprecedented.
TechCrunchAnthropic officially told by DOD that it's a supply chain risk even as Claude used in Iran
Mar 5, 2026InfoNewsPolicyIndustryThe Department of Defense has officially informed Anthropic's leadership that the company and its products are designated a supply chain risk, effective immediately, according to a senior department official. The label requires defense vendors and contractors to certify they do not use Anthropic's models in their Pentagon work, and Anthropic says it will challenge the designation in court.
CNBC TechnologyTech industry group expresses 'concern' to Pete Hegseth over supply chain risk label
Mar 4, 2026InfoNewsPolicyIndustryThe Information Technology Industry Council, whose members include Nvidia, Google, Microsoft, Apple, Amazon and Anthropic, sent a letter to Defense Secretary Pete Hegseth expressing concern over the designation of a U.S. company as a supply chain risk. The letter does not name Anthropic, which received the label after failing to reach terms with the Defense Department. The group argues that contract disputes should be resolved through negotiation or by selecting alternate providers, and that such emergency authorities are reserved for foreign adversaries.
CNBC TechnologyGHSA-5hwf-rc88-82xm: Fickling missing RCE-capable modules in UNSAFE_IMPORTS
Mar 4, 2026HighVulnerabilitySecurityfickling versions up to and including 0.1.8 have an incomplete UNSAFE_IMPORTS blocklist that omits the stdlib modules uuid, _osx_support and _aix_support. Functions in these modules, such as uuid._get_command_stdout, _aix_support._read_cmd_output and _osx_support._find_build_tool, call subprocess.Popen() or os.system() with attacker-controlled arguments. A malicious pickle importing them passes fickling's UnsafeImports and NonStandardImports checks, and pickle.loads() runs the command.
Fix: Assessment: the modules uuid, _osx_support and _aix_support were added to the blocklist of unsafe imports (https://github.com/trailofbits/fickling/commit/ffac3479dbb97a7a1592d85991888562d34dd05b).
GitHub Advisory DatabaseTech workers urge DOD, Congress to withdraw Anthropic label as a supply-chain risk
Mar 2, 2026InfoNewsPolicyIndustryHundreds of tech workers signed an open letter urging the Department of Defense to withdraw its designation of Anthropic as a supply-chain risk, and asking Congress to examine whether such authorities against an American technology company are appropriate. The designation followed Anthropic's refusal to give the military unrestricted access to its AI systems, after it declined to allow mass surveillance of Americans or autonomous weapons without a human in the loop. Anthropic said the designation is legally unsound and that it would challenge it in court.
TechCrunchNew Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Mar 2, 2026MediumNewsSecurityIndustryPalo Alto Networks Unit 42 researcher Gal Weizman reported CVE-2026-0628 (CVSS 8.8), an insufficient policy enforcement flaw in the WebView tag of Google Chrome prior to 143.0.7499.192. A malicious extension with basic declarativeNetRequest permissions could inject JavaScript into the Gemini Live panel at gemini.google.com/app, gaining access to the camera and microphone, screenshots of any website, and local files. Google patched the flaw in early January 2026.
Fix: Fixed in Chrome version 143.0.7499.192/.193 for Windows/Mac and 143.0.7499.192 for Linux.
The Hacker NewsPentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
Feb 27, 2026InfoNewsPolicyIndustryU.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate Anthropic a "supply chain risk" after negotiations over Claude broke down. Anthropic had requested exceptions barring mass domestic surveillance of Americans and fully autonomous weapons. Anthropic called the designation "legally unsound" and said a designation under 10 USC 3252 can only extend to Claude's use in DoW contracts.
The Hacker NewsDefense secretary Pete Hegseth designates Anthropic a supply chain risk
Feb 27, 2026InfoNewsPolicyIndustryDefense Secretary Pete Hegseth designated Anthropic a "supply-chain risk" shortly after President Donald Trump announced a ban on Anthropic products across the federal government. The decision could immediately affect major tech companies that use Claude for Pentagon work, including Palantir and AWS, and it is unclear how far the Pentagon may extend restrictions to companies using Claude for non-national-security services.
The Verge (AI)Pentagon moves to designate Anthropic as a supply-chain risk
Feb 27, 2026InfoNewsPolicyIndustryPresident Trump directed federal agencies to cease using all Anthropic products after the company's public dispute with the Department of Defense, allowing a six-month phase-out. Secretary of Defense Pete Hegseth then directed the Department of War to designate Anthropic a Supply-Chain Risk to National Security, barring contractors and partners doing business with the US military from commercial activity with Anthropic. The dispute centered on Anthropic's refusal to allow its models to power mass domestic surveillance or fully autonomous weapons.
TechCrunchGHSA-mhc9-48gj-9gp3: Fickling has safety check bypass via REDUCE+BUILD opcode sequence
Feb 25, 2026MediumVulnerabilitySecurityThe Fickling pickle analyzer's five safety interfaces (is_likely_safe(), check_safety(), the --check-safety CLI flag, always_check_safety(), and the check_safety() context manager) report LIKELY_SAFE for pickle files that call dangerous stdlib functions when a REDUCE opcode is followed by a BUILD opcode. The reporter shows this enables a backdoor network listener, process persistence, outbound exfiltration via smtplib.SMTP, and file creation, and that appending a trivial BUILD opcode eliminates detection. Affected versions are all versions through 0.1.7.
Fix: The source states: "It is believed that the analysis pass works as intended, `REDUCE` and `BUILD` are not at fault here. The few potentially unsafe modules have been added to the blocklist (https://github.com/trailofbits/fickling/commit/0c4558d950daf70e134090573450ddcedaf10400)."
GitHub Advisory DatabaseNew ‘Sandworm_Mode’ Supply Chain Attack Hits NPM
Feb 24, 2026MediumNewsSecurityIndustryA supply chain attack dubbed 'Sandworm_Mode' has hit NPM. The malicious code spreads like a worm, poisons AI assistants, exfiltrates secrets, and includes a destructive dead switch.
SecurityWeekAutonomous AI Agents Provide New Class of Supply Chain Attack
Feb 23, 2026MediumNewsSecurityIndustryA campaign targets crypto wallets and steals money. The source says its methodology has far wider potential and could be used by other attackers.
SecurityWeekCline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
Feb 20, 2026MediumNewsSecurityIndustryOn February 17, 2026, an unauthorized party used a compromised npm publish token to publish cline@2.3.0 of the Cline CLI, which added a postinstall script that runs npm install -g openclaw@latest. Anyone who installed that version during the roughly eight-hour window from 3:26 a.m. to 11:30 a.m. PT got OpenClaw installed on their machine. Cline says no other changes or malicious behavior were observed.
Fix: To mitigate the unauthorized publication, Cline maintainers released version 2.4.0, deprecated version 2.3.0, and revoked the compromised token. The npm publishing mechanism was updated to support OpenID Connect (OIDC) via GitHub Actions. Users are advised to update to the latest version, check their environment for unexpected installation of OpenClaw, and remove it if not required.
The Hacker NewsCVE-2026-1669: Keras arbitrary file read in model loading via HDF5 integration
Feb 11, 2026HighVulnerabilitySecurityCVE-2026-1669CVE-2026-1669 is an arbitrary file read flaw in the model loading mechanism (HDF5 integration) of Keras versions 3.0.0 through 3.13.1 on all supported platforms. A remote attacker can use a crafted .keras model file with HDF5 external dataset references to read local files and disclose sensitive information. Google Inc. rated it CVSS 4.0 7.1 (High), with network attack vector, no privileges required, and user interaction required.
NVD/CVE DatabaseCVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index.load_from_disk
Jan 12, 2026HighVulnerabilitySecurityCVE-2024-14021CVE-2024-14021 affects LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6. The unsafe deserialization flaw sits in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py, which calls pickle.load() on multi_embed_store.pkl from a user-supplied persist_dir without validation. An attacker who supplies a crafted persist directory containing a malicious pickle file can achieve arbitrary code execution when a victim loads the index from disk. VulnCheck rates it CVSS 4.0 8.4 (High); NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-14921: Hugging Face Transformers code execution via deserialization of model files
Dec 23, 2025HighVulnerabilitySecurityCVE-2025-14921CVE-2025-14921 is a remote code execution flaw in the Transformer-XL model handling of Hugging Face Transformers. The flaw sits in the parsing of model files, where user-supplied data is not properly validated, leading to deserialization of untrusted data. A remote attacker can execute code in the context of the current user, provided the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2025-14920: Hugging Face Transformers Perceiver deserialization leads to code execution
Dec 23, 2025HighVulnerabilitySecurityCVE-2025-14920CVE-2025-14920 is a remote code execution flaw in the Perceiver model of Hugging Face Transformers, caused by deserialization of untrusted data during parsing of model files. A remote attacker can run arbitrary code in the context of the current user, but only if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseGHSA-m84c-4c34-28gf: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
Jul 6, 2025MediumVulnerabilitySecurityCVE-2025-3108The run-llama/llama_index library's JsonPickleSerializer component, in versions v0.12.27 through v0.12.40, falls back to Python's pickle module. Its deserialization calls pickle.loads(), so processing untrusted data can execute arbitrary code, and attackers can craft malicious payloads to achieve full system compromise. The root cause is an insecure fallback strategy without sufficient input validation or protective safeguards.
Fix: Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things.
GitHub Advisory DatabaseCVE-2025-1945: picklescan flaw lets malicious pickles hide in PyTorch model ZIP archives
Mar 10, 2025CriticalVulnerabilitySecurityCVE-2025-1945picklescan before 0.0.23 fails to detect malicious pickle files embedded in PyTorch model archives when specific ZIP header flag bits are flipped. Such a file still loads through torch.load(), which can lead to arbitrary code execution when a compromised model is loaded. The source gives a Sonatype CVSS 4.0 score of 5.3 (MEDIUM) and CWE-345, while NIST's assessment is not yet provided.
Fix: The source links a fix commit (github.com/mmaitre314/picklescan/commit/e58e45e0d9e091159c1554f9b04828bbb40b9781) and advisory GHSA-w8jq-xcqf-f792, and the title indicates the issue is fixed in picklescan 0.0.23 or later.
NVD/CVE DatabaseCVE-2024-53880: NVIDIA Triton Inference Server integer overflow in model loading API
Feb 12, 2025MediumVulnerabilitySecurityCVE-2024-53880NVIDIA Triton Inference Server contains an integer overflow or wraparound vulnerability (CWE-190) in its model loading API. A user who loads a model with an extra-large file size can overflow an internal variable, which may lead to denial of service.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.