Critical severity9.1NVD Advisory· Published Jun 30, 2021· Updated Jun 17, 2026
CVE-2021-35958
CVE-2021-35958
Description
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not intended for untrusted archives
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TensorFlow/TensorFlowdescription
- Range: <=2.5.0
Patches
Vulnerability mechanics
References
5- docs.python.org/3/library/tarfile.htmlnvdThird Party Advisory
- github.com/tensorflow/tensorflow/blob/b8cad4c631096a34461ff8a07840d5f4d123ce32/tensorflow/python/keras/README.mdnvdThird Party Advisory
- github.com/tensorflow/tensorflow/blob/b8cad4c631096a34461ff8a07840d5f4d123ce32/tensorflow/python/keras/utils/data_utils.pynvdThird Party Advisory
- keras.io/api/nvdThird Party Advisory
- vuln.ryotak.me/advisories/52nvdThird Party Advisory
News mentions
0No linked articles in our index yet.