A AegiFlow
HIGHCVSS 8.8EPSS 0.5%

CVE-2026-12481

Keras: Lambda deserialization can bypass safe mode and execute code

Published
2026-07-03
Modified
2026-08-07
EPSS percentile
38%
Aliases
GHSA-5gwj-m78q-7pq3
Sources
github-advisory

Summary

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), bypassing the guard and allowing attacker-controlled `marshal` bytecode to be deserialized. Affected call sites include `keras.layers.deserialize(config)`, `keras.models.clone_model(model)`, and any direct invocation of `Lambda.from_config(config)` without an enclosing `SafeModeScope(True)`. This vulnerability can be exploited to achieve arbitrary OS-level code execution in the context of the server or user process.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIkeras3.12.3, 3.15.0

Remediation: Upgrade to 3.12.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.