Skip to content
KerasGHSA-x4wf-678h-2pmq

Keras code injection vulnerability

Critical9.8CVE-2024-3660 · Published Apr 16, 2024 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
keras
PyPI
< 2.13.1rc02.13.1rc0
Details and references

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-3660, PYSEC-2026-369

More Keras advisories

All Keras
DateAdvisory
Jan 82025keras Path Traversal vulnerability
CVE-2024-55459Mediumno fix yet
Mar 112025Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-1550Highfixed in 3.9.0
Aug 122025Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8747High8.8fixed in 3.11.0
Sep 192025Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-9906High7.3fixed in 3.11.0
Sep 192025The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9905Highfixed in 3.11.3
Oct 172025Keras framework vulnerable to deserialization of untrusted data
CVE-2025-49655Critical9.8fixed in 3.11.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.