CVE-2025-1550

EUVD-2025-7406
The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84.13%
Affected Products (NVD)
VendorProductVersion
keraskeras
3.0.0 ≤
𝑥
< 3.8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
keras
bullseye
2.3.1+dfsg-3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
keras
Azure Linux 3.0
0:3.3.3-2.azl3
fixed