JFrog Security Research
Model Threats
Discover
Follow JFrog Security
Home
Model Threats
Discover
Follow JFrog Security
< Back
Software Vulnerabilities
Last Updated On
11 Dec, 2025
178
Vulnerabilities
discovered
JFSA-2025-001648329
python-utcp untrusted Manual command execution
high
CVE-2025-14542
CVE-2025-14542
CVE-2025-14542
high
Discovered By
Or Peles
●
Published on
11 Dec, 2025
●
JFSA-2025-001648159
Litmus Chaos JWT Missing Entropy Privilege Escalation
high
CVE-2025-14261
CVE-2025-14261
CVE-2025-14261
high
Discovered By
Natan Nehorai
●
Published on
8 Dec, 2025
●
n8n Git Node RCE
high
CVE-2025-62726
CVE-2025-62726
CVE-2025-62726
high
Discovered By
Assaf Levkovich
●
Published on
4 Nov, 2025
●
JFSA-2025-001495652
DSPy sandbox escape arbitrary file read
medium
CVE-2025-12695
CVE-2025-12695
CVE-2025-12695
medium
Discovered By
Natan Nehorai
●
Published on
4 Nov, 2025
●
Cursor CLI Untrusted Project RCE
high
CVE-2025-61592
CVE-2025-61592
CVE-2025-61592
high
Discovered By
Assaf Levkovich
●
Published on
4 Nov, 2025
●
JFSA-2025-001495618
React Native CLI Command Injection
critical
CVE-2025-11953
CVE-2025-11953
CVE-2025-11953
critical
Discovered By
Or Peles
●
Published on
3 Nov, 2025
●
JFSA-2025-001494691
oatpp-mcp prompt hijacking
medium
CVE-2025-6515
CVE-2025-6515
CVE-2025-6515
medium
Discovered By
Ori Hollander
●
Published on
20 Oct, 2025
●
JFSA-2025-001471363
txtai arbitrary file write
high
CVE-2025-10854
CVE-2025-10854
CVE-2025-10854
high
Discovered By
Ori Hollander
●
Published on
22 Sep, 2025
●
XRAY-720930
PickleScan Unsafe Globals Check Bypass via Submodule Imports
critical
CVE-2025-10157
CVE-2025-10157
CVE-2025-10157
critical
Discovered By
David Cohen
●
Published on
21 Sep, 2025
●
XRAY-720938
PickleScan Bypass via ZIP file bad CRC
critical
CVE-2025-10156
CVE-2025-10156
CVE-2025-10156
critical
Discovered By
David Cohen
●
Published on
21 Sep, 2025
●
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18