Keras: tar extraction permits symlink-based path traversal
Low3.1CVE-2026-12482 · Published Jul 14, 2026 · updated Aug 10, 2026
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| keras PyPI | < 3.12.3 | 3.12.3 |
| >= 3.13.0, < 3.15.0 | 3.15.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2026-12482, PYSEC-2026-3630
- nvd.nist.gov/vuln/detail/CVE-2026-12482
- github.com/keras-team/keras/pull/23015
- github.com/keras-team/keras/pull/23165
- github.com/keras-team/keras/commit/9867df45c456dd1077a6243bb56219f66e288150
- github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedf
- github.com/keras-team/keras
- github.com/keras-team/keras/releases/tag/v3.12.3
- github.com/keras-team/keras/releases/tag/v3.15.0
- huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e
More Keras advisories
All Keras| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Keras model loading is vulnerable to denial of service through HDF5 shape bombs | Medium5.5 | 3.15.0 |
| Aug 2 | Keras: HDF5 links can disclose local file contents | Medium6.5 | 3.12.3+1 more |
| Jul 19 | Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data | High7.8 | 3.12.3+1 more |
| Jul 3 | Keras: Lambda deserialization can bypass safe mode and execute code | High8.8 | 3.12.3+1 more |
| Jul 1 | Keras: HDF5 virtual datasets can disclose local files | Medium5.5 | 3.12.3+1 more |
| Jun 22 | Keras: DiskIOStore permits path traversal through crafted layer names | Medium6.1 | 3.12.3+1 more |