High severity7.8NVD Advisory· Published Apr 13, 2026· Updated Jul 15, 2026
CVE-2026-1462
CVE-2026-1462
Description
A vulnerability in the TFSMLayer class of the keras package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of .keras models, even when safe_mode=True. This bypasses the security guarantees of safe_mode and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the from_config() method.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kerasPyPI | < 3.13.2 | 3.13.2 |
Affected products
6- osv-coords3 versionspkg:apk/chainguard/kubeflow-pipelines-visualization-serverpkg:apk/wolfi/kubeflow-pipelines-visualization-serverpkg:pypi/keras
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 3.13.2
Patches
Vulnerability mechanics
References
10- github.com/keras-team/keras/commit/b6773d3decaef1b05d8e794458e148cb362f163fnvdPatchWEB
- huntr.com/bounties/7e78d6f1-6977-4300-b595-e81bdbda331cnvdExploitThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:24977nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-1462nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/advisories/GHSA-4f3f-g24h-fr8mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-1462ghsaADVISORY
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1462.jsonnvdThird Party Advisory
- github.com/keras-team/keras/pull/22035ghsaWEB
- access.redhat.com/errata/RHSA-2026:37275nvd
News mentions
0No linked articles in our index yet.