Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-8747

Опубликовано: 11 авг. 2025
Источник: debian
EPSS Низкий

Описание

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kerasnot-affectedpackage

Примечания

  • Follow-up fix for CVE-2025-1550.

  • https://github.com/advisories/GHSA-c9rc-mg46-23w3

  • https://github.com/keras-team/keras/pull/21429 (v3.11.0)

EPSS

Процентиль: 0%
0.00006
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
13 дней назад

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

CVSS3: 7.8
nvd
13 дней назад

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

CVSS3: 8.8
github
12 дней назад

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

EPSS

Процентиль: 0%
0.00006
Низкий