KerasGHSA-x4wf-678h-2pmq
Keras code injection vulnerability
Critical9.8CVE-2024-3660 · Published Apr 16, 2024 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| keras PyPI | < 2.13.1rc0 | 2.13.1rc0 |
Details and references
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2024-3660, PYSEC-2026-369
More Keras advisories
All Keras| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 82025 | keras Path Traversal vulnerability CVE-2024-55459Mediumno fix yet | Medium | No fix yet |
| Mar 112025 | Arbitrary Code Execution via Crafted Keras Config for Model Loading CVE-2025-1550Highfixed in 3.9.0 | High | 3.9.0 |
| Aug 122025 | Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality CVE-2025-8747High8.8fixed in 3.11.0 | High8.8 | 3.11.0 |
| Sep 192025 | Keras is vulnerable to Deserialization of Untrusted Data CVE-2025-9906High7.3fixed in 3.11.0 | High7.3 | 3.11.0 |
| Sep 192025 | The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded. CVE-2025-9905Highfixed in 3.11.3 | High | 3.11.3 |
| Oct 172025 | Keras framework vulnerable to deserialization of untrusted data CVE-2025-49655Critical9.8fixed in 3.11.3 | Critical9.8 | 3.11.3 |