A AegiFlow
MEDIUMCVSS 5.5EPSS 0.1%

CVE-2026-12480

Keras: HDF5 virtual datasets can disclose local files

Published
2026-07-01
Modified
2026-08-07
EPSS percentile
3%
Aliases
GHSA-26c4-7vv6-867j
Sources
github-advisory

Summary

Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.3 and 3.15.0.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIkeras3.12.3, 3.15.0

Remediation: Upgrade to 3.12.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.