Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
High7.8CVE-2026-12484 · Published Jul 19, 2026 · updated Aug 10, 2026
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the absence of an ambient safe mode state permits unsafe deserialization by default. This issue can lead to arbitrary code execution if untrusted Keras layer configurations are processed using this method. The vulnerability arises because the method does not enforce safe deserialization practices unless explicitly guarded by Keras safe mode.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| keras PyPI | < 3.12.3 | 3.12.3 |
| >= 3.13.0, < 3.15.0 | 3.15.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2026-12484, PYSEC-2026-3634
- nvd.nist.gov/vuln/detail/CVE-2026-12484
- github.com/keras-team/keras/pull/23048
- github.com/keras-team/keras/pull/23165
- github.com/keras-team/keras/commit/55888d3becbdbb45dc16a55b489900f911e2dde5
- github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedf
- github.com/keras-team/keras
- github.com/keras-team/keras/releases/tag/v3.12.3
- github.com/keras-team/keras/releases/tag/v3.15.0
- huntr.com/bounties/ab14df49-13b5-4442-b754-3189430bfa28
More Keras advisories
All Keras| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Keras model loading is vulnerable to denial of service through HDF5 shape bombs | Medium5.5 | 3.15.0 |
| Aug 2 | Keras: HDF5 links can disclose local file contents | Medium6.5 | 3.12.3+1 more |
| Jul 14 | Keras: tar extraction permits symlink-based path traversal | Low3.1 | 3.12.3+1 more |
| Jul 3 | Keras: Lambda deserialization can bypass safe mode and execute code | High8.8 | 3.12.3+1 more |
| Jul 1 | Keras: HDF5 virtual datasets can disclose local files | Medium5.5 | 3.12.3+1 more |
| Jun 22 | Keras: DiskIOStore permits path traversal through crafted layer names | Medium6.1 | 3.12.3+1 more |