CWE-1426: Improper Validation of Generative AI Output
The product invokes a generative AI/ML component whose behaviors and outputs cannot be directly controlled, but the product does not validate or insufficiently validates the outputs to ensure that they align with the intended security, content, or privacy policy.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-55074 — Channel member objects leak read status
- CVE-2025-31363 — Data exfiltration via AI plugin Jira tool
Recently published
- CVE-2025-55074 — Channel member objects leak read status
- CVE-2025-31363 — Data exfiltration via AI plugin Jira tool