← Vulnerability feed

Vulnerability record · CVE-2025-8747 · published 11 August 2025

CVE-2025-8747: Keras deserialization of untrusted data vulnerability

Keras · Keras

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

8.6 CVSS 4.0 High EPSS 0.12% · top 98.5% CWE-502 · Deserialization of untrusted data
8.6CVSS 4.0 base score
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8747 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-12481Keras deserialization of untrusted data vulnerabilityA vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la…EPSS 0.72%9.8CVE-2024-3660Keras code injection vulnerabilityA arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions…EPSS 1.7%8.6CVE-2025-9906Keras deserialization of untrusted data vulnerabilityThe Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted …EPSS 0.20%8.1CVE-2026-11816Keras path traversal vulnerabilityKeras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py…EPSS 0.56%7.8CVE-2026-1462Keras deserialization of untrusted data vulnerabilityA vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…EPSS 0.40%7.3CVE-2025-9905Keras improper control of dynamically-managed code vulnerabilityThe Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted …EPSS 0.22%7.3CVE-2025-1550Keras code injection vulnerabilityThe Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras arch…EPSS 2.6%7.1CVE-2026-1669Keras information exposure vulnerabilityArbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remo…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2025-8747), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.