๐Ÿ” CVE Alert

CVE-2026-12479

MEDIUM 6.1

Path Traversal in keras-team/keras

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths without sanitizing for parent directory components (`..`). While forward slashes (`/`) are restricted in layer names, directory traversal sequences are not. This allows an attacker to craft a malicious Keras model that, when saved or loaded, can escape the intended temporary working directory and perform unauthorized file system operations, such as creating directories or writing files in arbitrary locations.

CWE CWE-22
Vendor keras-team
Product keras-team/keras
Published Jun 22, 2026
Last Updated Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for keras-team keras-team/keras

Be the first to know when new medium vulnerabilities affecting keras-team keras-team/keras are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Affected Versions

keras-team / keras-team/keras
unspecified โ‰ค latest

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
huntr.com: https://huntr.com/bounties/188836b9-12fc-49c7-8dbf-04f60fe33743