Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12060

Опубликовано: 30 окт. 2025
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python tarfile weakness, identified as CVE-2025-4517. Note that upgrading Python to one of the versions that fix CVE-2025-4517 (e.g. Python 3.13.4) is not enough. One additionally needs to upgrade Keras to a version with the fix (Keras 3.12).

A path traversal flaw has been discovered in the keras Python library. when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Red Hat Trusted Artifact Signerrhtas/model-transparency-rhel9Not affected
Red Hat OpenShift AI 2.16rhoai/odh-modelmesh-runtime-adapter-rhel8FixedRHSA-2026:580725.03.2026
Red Hat OpenShift AI 2.22rhoai/odh-modelmesh-runtime-adapter-rhel9FixedRHSA-2025:2275904.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-kserve-agent-rhel9FixedRHSA-2025:2353117.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-kserve-controller-rhel9FixedRHSA-2025:2353117.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-kserve-router-rhel9FixedRHSA-2025:2353117.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-kserve-storage-initializer-rhel9FixedRHSA-2025:2353117.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-modelmesh-runtime-adapter-rhel9FixedRHSA-2025:2353117.12.2025
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9FixedRHSA-2025:2353117.12.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2407443keras: Keras Path Traversal Vulnerability

EPSS

Процентиль: 45%
0.00584
Низкий

8.3 High

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python tarfile weakness, identified as CVE-2025-4517. Note that upgrading Python to one of the versions that fix CVE-2025-4517 (e.g. Python 3.13.4) is not enough. One additionally needs to upgrade Keras to a version with the fix (Keras 3.12).

nvd
10 месяцев назад

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python tarfile weakness, identified as CVE-2025-4517. Note that upgrading Python to one of the versions that fix CVE-2025-4517 (e.g. Python 3.13.4) is not enough. One additionally needs to upgrade Keras to a version with the fix (Keras 3.12).

msrc
10 месяцев назад

Keras keras.utils.get_file Utility Path Traversal Vulnerability

debian
10 месяцев назад

The keras.utils.get_file API in Keras, when used with the extract=True ...

CVSS3: 9.8
github
9 месяцев назад

Keras Directory Traversal Vulnerability

EPSS

Процентиль: 45%
0.00584
Низкий

8.3 High

CVSS3