PT-2025-38517 · Keras+1 · Keras+1
Gabriele Digregorio
·
Publicado
2025-09-19
·
Atualizado
2026-01-19
·
CVE-2025-9905
CVSS v3.1
7.3
Alta
| Vetor | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keras (affected versions not specified)
Description
The
Model.load model method can be exploited to achieve arbitrary code execution, even when safe mode is enabled. This is possible by creating a specially crafted .h5 or .hdf5 model archive that, when loaded, triggers the execution of arbitrary code. The vulnerability stems from the fact that the safe mode=True option is not honored when reading .h5 archives. The issue involves the Lambda layer feature of Keras, which allows arbitrary Python code in the form of pickled code to be included within the model archive.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Keras