{"id":"GHSA-48g7-3x6r-xfhp","summary":"Arbitrary Code Execution via Crafted Keras Config for Model Loading","details":"### Impact\n\nThe Keras `Model.load_model` function permits arbitrary code execution, even with `safe_mode=True`, through a manually constructed, malicious `.keras` archive. By altering the `config.json` file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading.\n\n### Patches\n\nThis problem is fixed starting with version `3.9`.\n\n### Workarounds\n\nOnly load models from trusted sources and model archives created with Keras.\n\n### References\n\n- https://www.cve.org/cverecord?id=CVE-2025-1550\n- https://github.com/keras-team/keras/pull/20751","aliases":["CVE-2025-1550","PYSEC-2025-122"],"modified":"2026-09-10T03:50:56.790604392Z","published":"2025-03-11T20:07:32Z","database_specific":{"github_reviewed_at":"2025-03-11T20:07:32Z","nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/keras-team/keras/security/advisories/GHSA-48g7-3x6r-xfhp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1550"},{"type":"WEB","url":"https://github.com/keras-team/keras/pull/20751"},{"type":"WEB","url":"https://github.com/keras-team/keras/commit/e67ac8ffd0c883bec68eb65bb52340c7f9d3a903"},{"type":"PACKAGE","url":"https://github.com/keras-team/keras"},{"type":"WEB","url":"https://github.com/keras-team/keras/releases/tag/v3.9.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keras/PYSEC-2025-122.yaml"},{"type":"WEB","url":"https://towerofhanoi.it/writeups/cve-2025-1550"}],"affected":[{"package":{"name":"keras","ecosystem":"PyPI","purl":"pkg:pypi/keras"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.9.0"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.1.0","3.1.1","3.2.0","3.2.1","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.4.1","3.5.0","3.6.0","3.7.0","3.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-48g7-3x6r-xfhp/GHSA-48g7-3x6r-xfhp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}