Description
A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
3.0.0
Credits
JFrog Security Research Team
References
github.com/keras-team/keras/pull/21429
jfrog.com/blog/keras-safe_mode-bypass-vulnerability/