PT-2025-42617 · Google+1 · Keras+1

Published

2025-10-17

·

Updated

2025-11-25

·

CVE-2025-49655

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keras versions 3.11.0 through 3.11.2
Description The Keras framework is susceptible to a critical security issue stemming from unsafe deserialization of untrusted data. Specifically, when loading Keras files containing a maliciously crafted TorchModuleWrapper class, an attacker can execute arbitrary code on a user’s system. This is possible even when safe mode is enabled. The issue can be triggered through both local and remote files.
Recommendations Versions 3.11.0 through 3.11.2 should be updated. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-49655
GHSA-CVHH-Q5G5-QPRP

Affected Products

Debian
Keras