Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1462

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A vulnerability in the TFSMLayer class of the keras package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of .keras models, even when safe_mode=True. This bypasses the security guarantees of safe_mode and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the from_config() method.

A flaw was found in the keras package. This vulnerability allows an attacker to execute unauthorized code on a victim's system. It occurs when a victim loads a specially crafted .keras model, even if the safe_mode security feature is active. The issue arises because the keras package can unconditionally load external TensorFlow SavedModels without sufficient validation, thereby bypassing the intended security protections and leading to arbitrary code execution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-modelmesh-runtime-adapter-rhel8Affected
Red Hat OpenShift AI 2.25rhoai/odh-modelmesh-runtime-adapter-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 3.3rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9FixedRHSA-2026:3727509.07.2026
Red Hat OpenShift AI 3.3rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9FixedRHSA-2026:3727509.07.2026
Red Hat OpenShift AI 3.3rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9FixedRHSA-2026:3727509.07.2026
Red Hat OpenShift AI 3.3rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9FixedRHSA-2026:3727509.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2457856keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode

EPSS

Процентиль: 34%
0.00405
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

CVSS3: 7.8
nvd
4 месяца назад

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

CVSS3: 7.8
debian
4 месяца назад

A vulnerability in the `TFSMLayer` class of the `keras` package, versi ...

CVSS3: 8.8
github
4 месяца назад

Keras has an untrusted deserialization vulnerability

EPSS

Процентиль: 34%
0.00405
Низкий

7.8 High

CVSS3