Keras Security Update Advisory (CVE-2025-1550)

Keras Security Update Advisory (CVE-2025-1550)

Overview

 

We have released a security update to address a vulnerability in Keras. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-1550

 

Keras Versions: 3.0.0 and above and below 3.9.0

 

 

Resolved Vulnerabilities

 

Arbitrary file overwrite vulnerability due to insecure deserialization in Keras (CVE-2025-1550)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-1550

 

Keras Version: 3.9.0

 

 

References

 

[1] CVE-2025-1550 bypass via reuse of internal Keras functionality
https://github.com/keras-team/keras/security/advisories/GHSA-c9rc-mg46-23w3