Organisations using popular open-source AI tool urged to prioritise patching and investigate potential credential theft.