Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

Keras code injection vulnerability

GHSA-x4wf-678h-2pmq · CVE-2024-3660

Published · Modified

Description

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

Ready to move

Start Securing

Free, no credit card | First findings in minutes