Database/AI/ML frameworks & serving
Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`
CVSS 8.1CVE-2026-11816AI/ML frameworks & servingcurated
Impact
Path traversal in keras/src/utils/file_utils.py
Who can reach it
Customer-supplied archive
What to do
Upgrade to 3.14.0+
References
Related entries
- llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`CVE-2026-43629 · llama-server (KV cache state restore)High
- llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsCVE-2026-43632 · llama-server (tokenization endpoints)High
- NVIDIA NemoClaw: installation process executes untrusted codeCVE-2026-65081 · NVIDIA NemoClaw for Linux (installer)High
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyCVE-2026-65084 · NVIDIA NemoClaw for Linux (deployment process, TLS certificate validation)High
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowCVE-2026-65098 · NVIDIA NemoClaw for Linux (remote-access helper workflow)High
- NVIDIA NemoClaw: inference service comes up without authentication, reachable from the adjacent networkCVE-2026-65105 · NVIDIA NemoClaw for Linux (inference server setup)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.