Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD) instead of the actual extraction destination. When the process runs with CWD set to `/`, which is common in Docker containers, CI/CD runners, and Jupyter environments, the validation boundary become
Affected packages
- keras— before 3.14.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://access.redhat.com/security/cve/CVE-2026-11816
- https://bugzilla.redhat.com/show_bug.cgi?id=2487912
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11816.json
- https://github.com/keras-team/keras/commit/2465b6657b02c8eed308759b7e800e295ae01888
- https://huntr.com/bounties/a07e3983-7158-4419-af2b-38f1dea01a4f
- https://github.com/advisories/GHSA-hqp4-2352-xf5r
Structured record: https://osv.dev/vulnerability/PYSEC-2026-2324
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta