insidejob

Security Advisories

CVEs and security advisories affecting AI/ML packages. Sorted by severity.

critical 9.3 patched
CVE-2025-68664

LangChain Core serialization injection allows arbitrary code execution

langchain-core
critical 9.6 patched
CVE-2025-53773

GitHub Copilot prompt injection via PR descriptions enables RCE

github-copilot