Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58hv-7753-xmfq

Опубликовано: 14 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Keras: tar extraction permits symlink-based path traversal

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the filter_safe_tarinfos validation in keras/src/utils/file_utils.py. Specifically, symlink entries are not subjected to the same is_path_in_dir validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where filter_safe_tarinfos is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

Пакеты

Наименование

keras

pip
Затронутые версииВерсия исправления

< 3.12.3

3.12.3

Наименование

keras

pip
Затронутые версииВерсия исправления

>= 3.13.0, < 3.15.0

3.15.0

EPSS

Процентиль: 15%
0.00238
Низкий

3.1 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

CVSS3: 4.2
redhat
около 1 месяца назад

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

CVSS3: 6.5
nvd
около 1 месяца назад

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

CVSS3: 6.5
debian
около 1 месяца назад

A vulnerability in keras-team/keras version 3.12.0 allows an attacker ...

EPSS

Процентиль: 15%
0.00238
Низкий

3.1 Low

CVSS3

Дефекты

CWE-22