GHSA-cjgq-5qmw-rcj6Medium

keras Path Traversal vulnerability

Published
January 8, 2025
Last Modified
June 6, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

🎯 Affected products1

  • pip/keras:<= 3.7.0

🔗 References (7)