Skip to content
KerasGHSA-v2w2-w228-c444

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

High7.8CVE-2026-12484 · Published Jul 19, 2026 · updated Aug 10, 2026

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the absence of an ambient safe mode state permits unsafe deserialization by default. This issue can lead to arbitrary code execution if untrusted Keras layer configurations are processed using this method. The vulnerability arises because the method does not enforce safe deserialization practices unless explicitly guarded by Keras safe mode.

GitHub advisory

Affected versions

PackageAffectedFixed in
keras
PyPI
< 3.12.33.12.3
>= 3.13.0, < 3.15.03.15.0
Details and references

More Keras advisories

All Keras
Advisory
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Medium5.5Aug 10
Keras: HDF5 links can disclose local file contents
Medium6.5Aug 2
Keras: tar extraction permits symlink-based path traversal
Low3.1Jul 14
Keras: Lambda deserialization can bypass safe mode and execute code
High8.8Jul 3
Keras: HDF5 virtual datasets can disclose local files
Medium5.5Jul 1
Keras: DiskIOStore permits path traversal through crafted layer names
Medium6.1Jun 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.