Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-12060

29
FAUCET Score

CVE-2025-12060 is a path traversal vulnerability in the Keras keras.utils.get_file API when extracting tar archives with the 'extract=True' option. This flaw allows a remote attacker to write arbitrary files to any filesystem location by crafting a malicious tar archive containing special symlinks. Rated 8.9 HIGH on CVSS, the vulnerability has a low attack complexity and can lead to high impact across confidentiality, integrity, and availability. While it stems from an underlying Python tarfile weakness (CVE-2025-4517), upgrading Python alone is insufficient; Keras must also be updated to version 3.12. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, <= 3.11.3CPE match
cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.9HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 58th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

microsoftpatch availablevia msrc
Product: 20558-17084Fixed in: 3.3.3-5
microsoftpatch availablevia msrc
Product: azl3 keras 3.3.3-4 on Azure Linux 3.0Fixed in: 3.3.3-5
pippatch availablevia ghsa
Product: kerasFixed in: 3.12.0
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.22Fixed in: rhoai/odh-modelmesh-runtime-adapter-rhel9:sha256:1dd295d8062d8846ffb2534b2597e2791bd67387904b3d4ccf58cf3424d3250b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-router-rhel9:sha256:974dd5577124715f30df61d06aba22d95bc5f02103ab1b518eb517ed09284740
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-storage-initializer-rhel9:sha256:e9a1cdebc0511256b293f04741e81461d8113ef4cc891a9d85683aa862baaf7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-modelmesh-runtime-adapter-rhel9:sha256:bf9194f8e0885012b14da1cbe9a95e4b75bc80c8eada16b25e391ce035ba29d0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:sha256:229f2f2ee3b7e63bf17bf6739f3ee69fc87d9070ace1edec5d766f758e04ade1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:sha256:2f49b2e93ebc766c86404027e25bc433c4a093494c02f18b7c038bda85525cf0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:sha256:514e9edc09ab789ef1b409e1361d8be90dbfbd231eaad627e69f2301dd634934
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:sha256:1ecfb6fd3f5f223ff60e90e9ed45d393447f95de6b91451c1614bc69e042ec95
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-controller-rhel9:sha256:c3627352344b43f17fe4ae467891b2ebd4332a642071b5ff3c0cf81d269f8280
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-agent-rhel9:sha256:5a0d462e652464ae21e9152b6eac7d95c05d9d3d6884a3f1590c6194bda64ae7
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-modelmesh-runtime-adapter-rhel8

Vendor Advisories (3)

pipGHSA-hjqc-jx6g-rwp9high

Keras Directory Traversal Vulnerability

Dec 2, 2025
redhatCVE-2025-12060Important

keras: Keras Path Traversal Vulnerability

Oct 30, 2025
microsoft2025-Oct/CVE-2025-12060Important

Keras keras.utils.get_file Utility Path Traversal Vulnerability

Oct 14, 2025

References

github.com / keras-team/keras/pull/21760
github.com / keras-team/keras/security/advisories/GHSA-hjqc-jx6g-rwp9