GHSA-58hv-7753-xmfq
Keras: tar extraction permits symlink-based path traversal
Quick fix
GHSA-58hv-7753-xmfq — keras: upgrade to the fixed version with the command below.
pip install --upgrade 'keras>=3.12.3' Details
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-12482 [ADVISORY]
- https://github.com/keras-team/keras/pull/23015 [WEB]
- https://github.com/keras-team/keras/pull/23165 [WEB]
- https://github.com/keras-team/keras/commit/9867df45c456dd1077a6243bb56219f66e288150 [WEB]
- https://github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedf [WEB]
- https://github.com/keras-team/keras [PACKAGE]
- https://github.com/keras-team/keras/releases/tag/v3.12.3 [WEB]
- https://github.com/keras-team/keras/releases/tag/v3.15.0 [WEB]
- https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e [WEB]