Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-1550

52
FAUCET Score

CVE-2025-1550 describes a critical arbitrary code execution vulnerability in the Keras Model.load_model function, affecting Keras versions. An attacker can craft a malicious .keras archive, even with safe_mode enabled, to execute arbitrary Python code by manipulating the config.json file within the archive. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not yet on the CISA KEV list, public exploit code exists on ExploitDB (EDB-52359) and Nuclei templates are available, indicating a high potential for exploitation, despite limited community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.8.0CPE matchmatch criteria
cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.80%
Probability of exploitation in next 30 days
EPSS Percentile
85.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Nuclei: CVE-2025-1550 · Sep 8, 2025
ExploitDB: EDB-52359 · Jul 16, 2025
This CVE's current EPSS score of 0.0280 is in the 76th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 keras 3.3.3-2 on Azure Linux 3.0Fixed in: 3.3.3-2
microsoftpatch availablevia msrc
Product: 19276-17084Fixed in: 3.3.3-2
pippatch availablevia ghsa
Product: kerasFixed in: 3.9.0
ciscovendor investigatingvia llm_extracted
curlvendor investigatingvia llm_extracted
View patch
denovendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
laravelvendor investigatingvia llm_extracted
View patch
naturalintelligencevendor investigatingvia llm_extracted

Vendor Advisories (10)

laravelllm-laravel-4afb2918efd49283HIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
naturalintelligencellm-naturalintelligence-f65cf84d85d48ce3HIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
denollm-deno-a94b2aa8d42a868cHIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
hyperledgerllm-hyperledger-446ae60842b29f54HIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
ciscollm-cisco-d2437fe142d1c212HIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
kerasllm-keras-ddd7a58b8e802e21HIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
curlllm-curl-de4b068c38553dabHIGH

CVE-2025-1550 bypass via reuse of internal Keras functionality

Aug 11, 2025
pipGHSA-48g7-3x6r-xfhphigh

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Mar 11, 2025
redhatCVE-2025-1550Important

keras: Arbitrary Code Execution via Crafted Keras Config for Model Loading

Mar 11, 2025
microsoft2025-Mar/CVE-2025-1550Important

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Mar 11, 2025

References

github.com / keras-team/keras/pull/20751
Issue TrackingPatch
towerofhanoi.it / writeups/cve-2025-1550
ExploitThird Party Advisory