CVE-2026-11816: Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `f...
Added to the CISA Known Exploited Vulnerabilities catalog on 11 Jun 2026. Vendor: AI/ML. Product: machine learning.
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (...
Required action: Review and patch if applicable to your AI infrastructure.