Skip to content
KerasGHSA-58hv-7753-xmfq

Keras: tar extraction permits symlink-based path traversal

Low3.1CVE-2026-12482 · Published Jul 14, 2026 · updated Aug 10, 2026

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

GitHub advisory

Affected versions

PackageAffectedFixed in
keras
PyPI
< 3.12.33.12.3
>= 3.13.0, < 3.15.03.15.0
Details and references

More Keras advisories

All Keras
Advisory
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Medium5.5Aug 10
Keras: HDF5 links can disclose local file contents
Medium6.5Aug 2
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
High7.8Jul 19
Keras: Lambda deserialization can bypass safe mode and execute code
High8.8Jul 3
Keras: HDF5 virtual datasets can disclose local files
Medium5.5Jul 1
Keras: DiskIOStore permits path traversal through crafted layer names
Medium6.1Jun 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.