PT-2024-27091 · Google+1 · Tensorflow+1

·

CVE-2024-3660

·

Published

2024-04-16

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow's Keras framework versions prior to 2.13
Description A code injection issue in TensorFlow's Keras framework allows attackers to execute arbitrary code with the same permissions as the application. This can be achieved by using a model that permits arbitrary code execution, regardless of the application's permissions. The vulnerability can be exploited when loading a model created with an older version, potentially bypassing a patch.
Recommendations For versions prior to 2.13, consider disabling the use of models created with older versions until a patch is available. As a temporary workaround, restrict the loading of models to minimize the risk of exploitation. Avoid using the LambdaLayer in Keras until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-67629
CVE-2024-3660
GHSA-X4WF-678H-2PMQ
PYSEC-2026-369

Affected Products

Debian
Tensorflow