<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:55:09.286601+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-9906</id>
    <title>CVE-2025-9906 — Arbitrary Code execution in Keras Safe Mode</title>
    <updated>2026-10-02T21:55:09.288155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Keras-team Keras</p>
<p>The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True.</p>
<p>One can create a specially crafted .keras model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved by crafting a special config.json (a file within the .keras archive) that will invoke keras.config.enable_unsafe_deserialization() to disable safe mode. Once safe mode is disable, one can use the Lambda layer feature of keras, which allows arbitrary Python code in the form of pickled code. Both can appear in the same archive. Simply the keras.config.enable_unsafe_deserialization() needs to appear first in the archive and the Lambda with arbitrary code needs to be second.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-9906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36fq-jgmw-4r9c</id>
    <title>GHSA-36fq-jgmw-4r9c — Keras is vulnerable to Deserialization of Untrusted Data</title>
    <updated>2026-10-02T21:55:09.288211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keras</p>
<p>### Arbitrary Code Execution in Keras</p>
<p>Keras versions prior to 3.11.0 allow for arbitrary code execution when loading a crafted `.keras` model archive, even when `safe_mode=True`.</p>
<p>The issue arises because the archive’s `config.json` is parsed before layer deserialization. This can invoke `keras.config.enable_unsafe_deserialization()`, effectively disabling safe mode from within the loading process itself. An attacker can place this call first in the archive and then include a `Lambda` layer whose function is deserialized from a pickle, leading to the execution of attacker-controlled Python code as soon as a victim loads the model file.</p>
<p>Exploitation requires a user to open an untrusted model; no additional privileges are needed. The fix in version 3.11.0 enforces safe-mode semantics *before* reading any user-controlled configuration and prevents the toggling of unsafe deserialization via the config file.</p>
<p>**Affected versions:** &lt; 3.11.0
**Patched version:** 3.11.0</p>
<p>It is recommended to upgrade to version 3.11.0 or later and to avoid opening untrusted model files.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36fq-jgmw-4r9c"/>
  </entry>
</feed>
