OVERVIEW CVE-2026-1462 is a critical deserialization vulnerability in Keras version 3.13.0 that permits loading of attacker-controlled TensorFlow SavedModels during the deserialization of .keras model files. This vulnerability undermines the security protections of Keras's safe_mode feature, which is designed to restrict potentially dangerous operations. The flaw stems from insufficient validation in the TFSMLayer class's from_config() method, which unconditionally loads external SavedModels without proper checks. SEVERITY The vulnerability carries a CVSS 3.0 score of 8.8 (HIGH) with a network-based attack vector requiring minimal complexity and no prior privileges, though user interaction is necessary. An attacker can achieve arbitrary code execution with the privileges of the user loading the malicious model, resulting in complete compromise of confidentiality, integrity, and availability. The attack requires social engineering to convince a user to load a crafted .keras file, but once successful, allows unrestricted command execution during model inference. EXPLOITATION STATUS No evidence of active exploitation or public exploit code availability has been documented, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.00065 indicates minimal current exploitation probability compared to historical averages. Community attention remains limited, as reflected in its inactive status on industry tracking lists, though this should not diminish the urgency of patching given the severity rating and potential impact to machine learning operations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.13.0CPE matchmatch criteria | cpe:2.3:a:keras:keras:3.13.0:*:*:*:*:*:*:* | ||
>= 2.25, < 2.25.7CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.