AI
Breaking Wire
Content
Ecosystem
Community
Pricing
AI Vulnerability Database
490 vulnerabilities tracked — CVEs, prompt injection, model exploits.
HIGH
GitHub Copilot Replicates Insecure Code Patterns Leading to Command Injection
GitHub Copilot
OpenAI Codex
20 Nov 2025
1 views
Unpatched
CRITICAL
CVE-2023-34349
Malicious `torchtriton` Package on PyPI Steals Sensitive Data from AI/ML Systems
Previous
Page 5 of 41
Next
Python environments where `torchtriton` was installed
8 June 2025
1 views
Patched
MEDIUM
Data Exfiltration via Adversarially Crafted Images in AWS Bedrock's Claude 3 Sonnet API
AWS Bedrock (Claude 3 Sonnet model)
Anthropic Claude 3 API
GCP Vertex AI (Gemini Pro Vision model)
12 Nov 2025
1 views
Unpatched
HIGH
CVE-2025-21884
NVIDIA CUDA Driver Race Condition Allows GPU Memory Access Across Kubernetes Pods
NVIDIA Linux Driver 550.x series (before 550.90.07)
NVIDIA Linux Driver 555.x series (before 555.52.04)
Kubernetes with NVIDIA GPU Operator
30 June 2025
1 views
Patched
HIGH
Indirect Prompt Injection in GitHub Copilot via Malicious Documentation Causes Credential Leak
GitHub Copilot
Microsoft Visual Studio Code
JetBrains IntelliJ IDEA with Copilot plugin
22 Jan 2026
1 views
Unpatched
CRITICAL
Hugging Face Inference Infrastructure Compromise via Malicious Model with `trust_remote_code=True`
Hugging Face Hub
Hugging Face Transformers < 4.45.0
AWS SageMaker
GCP Vertex AI
+1 more
8 Sept 2025
1 views
Patched
HIGH
Hugging Face Hub Misconfiguration Leaks Sensitive Tokens in Multi-Tenant Inference Environments
Hugging Face Text Generation Inference (TGI) < 1.1.0
Hugging Face Inference Endpoints (prior to Oct 2023 patch)
22 June 2025
1 views
Patched
HIGH
CVE-2024-0072
NVIDIA GPU Driver Use-After-Free Allows Privilege Escalation from Containerized Workloads
NVIDIA GPU Driver (Linux) < 535.161.07
NVIDIA GPU Driver (Linux) < 545.29.06
NVIDIA GPU Driver (Linux) < 550.54.14
18 Mar 2025
1 views
Patched
MEDIUM
GitHub Copilot Suggests Insecure Code Patterns Leading to CWE-79 and CWE-89 Vulnerabilities
GitHub Copilot (all versions)
1 Aug 2025
1 views
Unpatched
CRITICAL
CVE-2023-52303
Malicious PyPI Package 'torchtriton' Steals Sensitive Data from AI/ML Developers
torchtriton (PyPI package) versions 2.1.0
10 Feb 2025
1 views
Patched
CRITICAL
Indirect Prompt Injection in LangChain ReAct Agents Allows Arbitrary Code Execution
LangChain <0.1.0 (with default tool configurations)
15 Apr 2025
1 views
Unpatched
CRITICAL
Unauthenticated Access to Azure OpenAI Fine-Tuned Models via Misconfigured Network ACLs
Azure OpenAI Service
5 Oct 2025
1 views
Unpatched