{"id":"CVE-2025-8747","aliases":["GHSA-c9rc-mg46-23w3","PYSEC-2025-75"],"url":"https://o3.security/vulnerability/CVE-2025-8747","summary":"Keras safe_mode bypass allows arbitrary code execution when loading a malicious model.","details":"A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.","published":"2025-08-11T07:21:16.619Z","modified":"2026-08-07T11:50:26.127550700Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keras","fixedVersion":"3.11.0"}],"fix":{"url":"https://github.com/keras-team/keras/pull/21429","label":"keras-team/keras#21429"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8747.json"},{"type":"ADVISORY","url":"https://jfrog.com/blog/keras-safe_mode-bypass-vulnerability/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8747"},{"type":"FIX","url":"https://github.com/keras-team/keras/pull/21429"},{"type":"PACKAGE","url":"https://github.com/keras-team/keras"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:26.127550700Z"}}