Database/AI/ML frameworks & serving
Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loading
CVSS 9.8CVE-2024-3660AI/ML frameworks & servingcurated
Impact
Arbitrary code injection in Keras < 2.13 via Lambda-layer model loading
Who can reach it
Customer-supplied .h5 model
What to do
Rebuild images off TF/Keras < 2.13; no runtime mitigation
References
Related entries
- Gradio: Code injection via `gradio/component_meta.py`CVE-2024-39236 · GradioCritical
- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CVE-2024-46946 · langchain-experimentalCritical
- Gradio: SSRF from the file-upload/proxy pathCVE-2024-47167 · GradioCritical
- PyTorch (`torch.distributed` RemoteModule / RPC): Deserialization RCE across the distributed RPC channelCVE-2024-48063 · PyTorch (`torch.distributed` RemoteModule / RPC)Critical
- PyTorch Lightning: RCE via deserialization of untrusted checkpointCVE-2024-5452 · PyTorch LightningCritical
- vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypointsCVE-2024-9053 · vLLM (`AsyncEngineRPCServer`)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.