Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12482— Path Traversal via Symlink Name Validation Bypass in keras-team/keras

Quick assessment

Affected
keras-team keras-team/keras
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

keras-team keras-team/keras是keras-team团队的深度学习框架。 Keras 3 3.12.0版本存在路径遍历漏洞,该漏洞源于在 中对tar归档的 验证存在绕过问题,符号链接条目未经过 验证,可能导致基于符号链接的文件读取、文件覆盖或目录逃逸攻击。

AI Predicted 8.1 Difficulty: Easy EPSS 0.33% · P24

Affected Version Matrix 1

VendorProduct Version RangeStatus
keras-team keras-team/keras unspecified≤ latest affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12482

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path Traversal via Symlink Name Validation Bypass in keras-team/keras
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
Keras 3 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
keras-team keras-team/keras是keras-team团队的深度学习框架。 Keras 3 3.12.0版本存在路径遍历漏洞,该漏洞源于在`keras/src/utils/file_utils.py`中对tar归档的`filter_safe_tarinfos`验证存在绕过问题,符号链接条目未经过`is_path_in_dir`验证,可能导致基于符号链接的文件读取、文件覆盖或目录逃逸攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
keras-team keras-team/keras unspecified ~ latest -

II. Public POCs for CVE-2026-12482

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12482

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12482 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12482

No comments yet


Leave a comment