Skip to content
KerasGHSA-cvhh-q5g5-qprp

Keras framework vulnerable to deserialization of untrusted data

Critical9.8CVE-2025-49655 · Published Oct 17, 2025 · updated Jun 29, 2026

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing a TorchModuleWrapper class to run arbitrary code on an end user’s system when loaded despite safe mode being enabled. The vulnerability can be triggered through both local and remote files.

GitHub advisory

Affected versions

PackageAffectedFixed in
keras
PyPI
>= 3.11.0, < 3.11.33.11.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2025-49655, PYSEC-2026-368

More Keras advisories

All Keras
Advisory
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
High7.1Feb 18
Keras Directory Traversal Vulnerability
High9.8Dec 2, 2025
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
MediumOct 29, 2025
Keras: code execution
HighSep 19, 2025
Keras is vulnerable to Deserialization of Untrusted Data
High7.3Sep 19, 2025
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
High8.8Aug 12, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.