Skip to content
KerasGHSA-cjgq-5qmw-rcj6

keras Path Traversal vulnerability

MediumCVE-2024-55459 · Published Jan 8, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
keras
PyPI
<= 3.7.0No fix yet
Details and references

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2024-55459, PYSEC-2025-121

More Keras advisories

All Keras
DateAdvisory
Mar 112025Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-1550Highfixed in 3.9.0
Aug 122025Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8747High8.8fixed in 3.11.0
Sep 192025Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-9906High7.3fixed in 3.11.0
Sep 192025The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9905Highfixed in 3.11.3
Apr 162024Keras code injection vulnerability
CVE-2024-3660Critical9.8fixed in 2.13.1rc0
Oct 172025Keras framework vulnerable to deserialization of untrusted data
CVE-2025-49655Critical9.8fixed in 3.11.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.