Database/AI/ML frameworks & serving
Keras: Code execution from crafted `.keras` archive despite safe mode
CVSS 7.3CVE-2025-9906AI/ML frameworks & servingcurated
Impact
Code execution from crafted .keras archive despite safe mode
Who can reach it
Customer-supplied model file
What to do
Upgrade; same class as above
References
Related entries
- Keras: Deserialization of untrusted data in 3.11.0–3.11.2CVE-2025-49655 · KerasCritical
- Keras: Safe-mode bypass in Keras 3.0.0–3.10.0CVE-2025-8747 · KerasHigh
- MLflow (artifact handler): Directory traversalCVE-2026-2033 · MLflow (artifact handler)High
- Jupyter Server (Origin validation): `re.match` used for Origin validationCVE-2026-40110 · Jupyter Server (Origin validation)High
- JupyterHub: A user granted limited access can escalateCVE-2024-41942 · JupyterHubHigh
- Weaviate: Crafted entry name with an absolute pathCVE-2025-67818 · WeaviateHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.