CVE-2026-1462
published 2026-04-13CVE-2026-1462: A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.40%
33.8th percentile
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keras-team | keras-team_keras | >= unspecified < 3.13.2 | 3.13.2 |
| keras | keras | — | — |
| keras | keras | >= 0 < 3.13.2 | 3.13.2 |
| redhat | openshift_ai | >= 2.25 < 2.25.7 | 2.25.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4f3f-g24h-fr8m: A vulnerability in the `TFSMLayer` class of the `keras` package, version 3
ghsa_unreviewed·2026-04-13
CVE-2026-1462 [HIGH] CWE-502 GHSA-4f3f-g24h-fr8m: A vulnerability in the `TFSMLayer` class of the `keras` package, version 3
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.
GHSA
Keras has an untrusted deserialization vulnerability
ghsa·2026-04-13
CVE-2026-1462 [HIGH] CWE-502 Keras has an untrusted deserialization vulnerability
Keras has an untrusted deserialization vulnerability
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.
VulDB
keras up to 3.13.1 TFSMLayer from_config deserialization (EUVD-2026-21970)
vuldb·2026-04-13·CVSS 8.8
CVE-2026-1462 [HIGH] keras up to 3.13.1 TFSMLayer from_config deserialization (EUVD-2026-21970)
A vulnerability classified as critical was found in keras up to 3.13.1. This impacts the function from_config of the component TFSMLayer. The manipulation results in deserialization.
This vulnerability was named CVE-2026-1462. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
Red Hat
keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode
vendor_redhat·2026-04-13·CVSS 8.8
CVE-2026-1462 [HIGH] CWE-502 keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode
keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode
A flaw was found in the `keras` package. This vulnerability allows an attacker to execute unauthorized code on a victim's system. It occurs when a victim loads a specially crafted `.keras` model, even if the `safe_mode` security feature is active. The issue arises because the `keras` package can unconditionally load external TensorFlow SavedModels without sufficient validation, thereby bypassing the intended security protections and leading to arbitrary code execution.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Pack
No detection rules found.
No public exploits indexed.
https://github.com/keras-team/keras/commit/b6773d3decaef1b05d8e794458e148cb362f163fhttps://huntr.com/bounties/7e78d6f1-6977-4300-b595-e81bdbda331chttps://access.redhat.com/errata/RHSA-2026:24977https://access.redhat.com/errata/RHSA-2026:37275https://access.redhat.com/security/cve/CVE-2026-1462https://bugzilla.redhat.com/show_bug.cgi?id=2457856https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1462.json
2026-04-13
Published