KerasGHSA-cvhh-q5g5-qprp
Keras framework vulnerable to deserialization of untrusted data
Critical9.8CVE-2025-49655 · Published Oct 17, 2025 · updated Jun 29, 2026
Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing a TorchModuleWrapper class to run arbitrary code on an end user’s system when loaded despite safe mode being enabled. The vulnerability can be triggered through both local and remote files.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| keras PyPI | >= 3.11.0, < 3.11.3 | 3.11.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2025-49655, PYSEC-2026-368
More Keras advisories
All Keras| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 18 | Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading | High7.1 | 3.12.1+1 more |
| Dec 22025 | Keras Directory Traversal Vulnerability | High9.8 | 3.12.0 |
| Oct 292025 | Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery | Medium | 3.12.0 |
| Sep 192025 | Keras: code execution | High | 3.11.3 |
| Sep 192025 | Keras is vulnerable to Deserialization of Untrusted Data | High7.3 | 3.11.0 |
| Aug 122025 | Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality | High8.8 | 3.11.0 |