CVE-2026-12482
Description
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the filter_safe_tarinfos validation in keras/src/utils/file_utils.py. Specifically, symlink entries are not subjected to the same is_path_in_dir validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where filter_safe_tarinfos is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kerasPyPI | < 3.12.3 | 3.12.3 |
kerasPyPI | >= 3.13.0, < 3.15.0 | 3.15.0 |
Affected products
2Patches
Vulnerability mechanics
References
9- huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6envdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-58hv-7753-xmfqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-12482ghsaADVISORY
- github.com/keras-team/keras/commit/9867df45c456dd1077a6243bb56219f66e288150ghsaWEB
- github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedfghsaWEB
- github.com/keras-team/keras/pull/23015ghsaWEB
- github.com/keras-team/keras/pull/23165ghsaWEB
- github.com/keras-team/keras/releases/tag/v3.12.3ghsaWEB
- github.com/keras-team/keras/releases/tag/v3.15.0ghsaWEB
News mentions
0No linked articles in our index yet.