{"id":"CVE-2026-12482","summary":"Path Traversal via Symlink Name Validation Bypass in keras-team/keras","details":"A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.","aliases":["GHSA-58hv-7753-xmfq","PYSEC-2026-3630"],"modified":"2026-08-12T03:51:39.201171496Z","published":"2026-07-14T05:13:07.252Z","database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12482.json","cna_assigner":"@huntr_ai"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12482.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12482"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keras-team/keras","events":[{"introduced":"adbfd13426a0da9864d9a0fcd5be5eed74ca341f"},{"last_affected":"adbfd13426a0da9864d9a0fcd5be5eed74ca341f"}],"database_specific":{"cpe":"cpe:2.3:a:keras:keras:3.12.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.12.0"},{"last_affected":"3.12.0"}],"source":"CPE_STRING"}}],"versions":["3.12.0","v3.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12482.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}