PT-2025-42617 · Google+1 · Keras+1

CVE-2025-49655

·

Published

2025-10-17

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keras versions 3.11.0 through 3.11.2
Description The Keras framework is susceptible to a critical security issue stemming from unsafe deserialization of untrusted data. Specifically, when loading Keras files containing a maliciously crafted TorchModuleWrapper class, an attacker can execute arbitrary code on a user’s system. This is possible even when safe mode is enabled. The issue can be triggered through both local and remote files.
Recommendations Versions 3.11.0 through 3.11.2 should be updated. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49655
GHSA-CVHH-Q5G5-QPRP
PYSEC-2026-368

Affected Products

Debian
Keras