<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:01:03 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-12060 — Keras keras.utils.get_file Utility Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-12060</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Keras&lt;/p&gt;
&lt;p&gt;The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python&amp;#39;s tarfile.extractall function without the filter=&amp;#34;data&amp;#34; feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python tarfile weakness, identified as CVE-2025-4517. Note that upgrading Python to one of the versions that fix CVE-2025-4517 (e.g. Python 3.13.4) is not enough. One additionally needs to upgrade Keras to a version with the fix (Keras 3.12).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Keras&lt;/p&gt;
&lt;p&gt;The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python&amp;#39;s tarfile.extractall function without the filter=&amp;#34;data&amp;#34; feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when extracted, allows them to write arbitrary files to any location on the filesystem outside of the intended destination folder. This vulnerability is linked to the underlying Python tarfile weakness, identified as CVE-2025-4517. Note that upgrading Python to one of the versions that fix CVE-2025-4517 (e.g. Python 3.13.4) is not enough. One additionally needs to upgrade Keras to a version with the fix (Keras 3.12).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-12060</guid>
    </item>
    <item>
      <title>GHSA-hjqc-jx6g-rwp9 — Keras Directory Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjqc-jx6g-rwp9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Keras&amp;#39;s `keras.utils.get_file()` function is vulnerable to directory traversal attacks despite implementing `filter_safe_paths()`. The vulnerability exists because `extract_archive()` uses Python&amp;#39;s `tarfile.extractall()` method without the security-critical `filter=&amp;#34;data&amp;#34;` parameter. A PATH_MAX symlink resolution bug occurs before path filtering, allowing malicious tar archives to bypass security checks and write files outside the intended extraction directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause Analysis&lt;/p&gt;
&lt;p&gt;**Current Keras Implementation**
```python
# From keras/src/utils/file_utils.py#L121
if zipfile.is_zipfile(file_path):
    # Zip archive.
    archive.extractall(path)
else:
    # Tar archive, perhaps unsafe. Filter paths.
    archive.extractall(path, members=filter_safe_paths(archive))
```&lt;/p&gt;
&lt;p&gt;### The Critical Flaw&lt;/p&gt;
&lt;p&gt;While Keras attempts to filter unsafe paths using `filter_safe_paths()`, this filtering happens after the tar archive members are parsed and before actual extraction. However, the PATH_MAX symlink resolution bug occurs during extraction, not during member enumeration.&lt;/p&gt;
&lt;p&gt;**Exploitation Flow:**
1. **Archive parsing**: `filter_safe_paths()` sees symlink paths that appear safe
2. **Extraction begins**: `extractall()` processes the filtered members
3. **PATH_MAX bug triggers**: Symlink resolution fails due to path length limits
4. **Security bypass**: Failed resolution causes literal path interpretation
5. **Directory traversal**: Files written outside intended dire…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Keras&amp;#39;s `keras.utils.get_file()` function is vulnerable to directory traversal attacks despite implementing `filter_safe_paths()`. The vulnerability exists because `extract_archive()` uses Python&amp;#39;s `tarfile.extractall()` method without the security-critical `filter=&amp;#34;data&amp;#34;` parameter. A PATH_MAX symlink resolution bug occurs before path filtering, allowing malicious tar archives to bypass security checks and write files outside the intended extraction directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause Analysis&lt;/p&gt;
&lt;p&gt;**Current Keras Implementation**
```python
# From keras/src/utils/file_utils.py#L121
if zipfile.is_zipfile(file_path):
    # Zip archive.
    archive.extractall(path)
else:
    # Tar archive, perhaps unsafe. Filter paths.
    archive.extractall(path, members=filter_safe_paths(archive))
```&lt;/p&gt;
&lt;p&gt;### The Critical Flaw&lt;/p&gt;
&lt;p&gt;While Keras attempts to filter unsafe paths using `filter_safe_paths()`, this filtering happens after the tar archive members are parsed and before actual extraction. However, the PATH_MAX symlink resolution bug occurs during extraction, not during member enumeration.&lt;/p&gt;
&lt;p&gt;**Exploitation Flow:**
1. **Archive parsing**: `filter_safe_paths()` sees symlink paths that appear safe
2. **Extraction begins**: `extractall()` processes the filtered members
3. **PATH_MAX bug triggers**: Symlink resolution fails due to path length limits
4. **Security bypass**: Failed resolution causes literal path interpretation
5. **Directory traversal**: Files written outside intended dire…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjqc-jx6g-rwp9</guid>
    </item>
  </channel>
</rss>
