{"id":"CVE-2025-49655","aliases":["GHSA-cvhh-q5g5-qprp","PYSEC-2026-368"],"url":"https://o3.security/vulnerability/CVE-2025-49655","summary":"Keras framework vulnerable to deserialization of untrusted data","details":"Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing a TorchModuleWrapper class to run arbitrary code on an end user’s system when loaded despite safe mode being enabled. The vulnerability can be triggered through both local and remote files.","published":"2025-10-17T15:20:27.308Z","modified":"2026-08-12T03:51:42.184157192Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00699,"percentile":0.50356,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keras","fixedVersion":"3.11.3"}],"fix":{"url":"https://github.com/keras-team/keras/pull/21575","label":"keras-team/keras#21575"},"references":[{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-10-keras/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49655.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49655"},{"type":"FIX","url":"https://github.com/keras-team/keras/pull/21575"},{"type":"PACKAGE","url":"https://github.com/keras-team/keras"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-10-keras"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.184157192Z"}}