Critical Analysis: CVE-2026-11816 - Keras versions prior to 3.14.0 are vulnerable to a path trav... — June 18, 2026

Published 18 Jun 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

Initial Discovery and Context Alright, let’s talk about CVE-2026-11816, a path traversal vulnerability in Keras versions prior to 3.14.0, specifically impacting the archive extraction utilities within keras/src/utils/file_utils.py . This one popped up on my radar recently, and it's a classic example of why seemingly innocuous file operations can have severe security implications. The vulnerability stems from inadequately sanitized archive member names during extraction, primarily within the filter_safe_tarinfos() and extract_archive() functions. Keras, as we all know, is a high-level API for building and training deep learning models, often used for diverse applications ranging from research to production deployments. This means instances of Keras can be found in development environments, CI/CD pipelines, and even customer-facing applications that might involve model updates or dataset i