VDB
KO
CRITICAL 9.8

GHSA-x4wf-678h-2pmq

Keras code injection vulnerability

Details

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / keras
Introduced in: 0 Fixed in: 2.13.1rc0
Fix pip install --upgrade 'keras>=2.13.1rc0'

References