Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-48g7-3x6r-xfhp

больше 1 года назад

Arbitrary Code Execution via Crafted Keras Config for Model Loading

EPSS: Низкий
ubuntu логотип

CVE-2025-1550

больше 1 года назад

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-1550

больше 1 года назад

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-1550

больше 1 года назад

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2025-1550

около 1 года назад

Arbitrary Code Execution via Crafted Keras Config for Model Loading

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-1550

больше 1 года назад

The Keras Model.load_model function permits arbitrary code execution, ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2025-02637

больше 1 года назад

Уязвимость функции Keras Model.load_model библиотеки Keras, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-48g7-3x6r-xfhp

Arbitrary Code Execution via Crafted Keras Config for Model Loading

3%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-1550

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 9.8
3%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-1550

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 8.2
3%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-1550

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.

CVSS3: 9.8
3%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-1550

Arbitrary Code Execution via Crafted Keras Config for Model Loading

CVSS3: 9.8
3%
Низкий
около 1 года назад
debian логотип
CVE-2025-1550

The Keras Model.load_model function permits arbitrary code execution, ...

CVSS3: 9.8
3%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-02637

Уязвимость функции Keras Model.load_model библиотеки Keras, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.2
3%
Низкий
больше 1 года назад

Уязвимостей на страницу