VYPR

Torch

by Pypi

CVEs (1)

  • CVE-2026-12484HigJul 19, 2026
    risk 0.44cvss 7.8epss 0.00

    A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an…