PT-2025-38517 · Keras+1 · Keras+1

Gabriele Digregorio

·

Publicado

2025-09-19

·

Atualizado

2026-01-19

·

CVE-2025-9905

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keras (affected versions not specified)
Description The Model.load model method can be exploited to achieve arbitrary code execution, even when safe mode is enabled. This is possible by creating a specially crafted .h5 or .hdf5 model archive that, when loaded, triggers the execution of arbitrary code. The vulnerability stems from the fact that the safe mode=True option is not honored when reading .h5 archives. The issue involves the Lambda layer feature of Keras, which allows arbitrary Python code in the form of pickled code to be included within the model archive.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-67505
BDU:2026-07995
CVE-2025-9905
GHSA-36RR-WW3J-VRJV
GHSA-77WQ-646F-JRM2
PYSEC-2025-123

Produtos afetados

Debian
Keras