{"id":"CVE-2026-12482","aliases":["GHSA-58hv-7753-xmfq"],"title":"Keras: tar extraction permits symlink-based path traversal","summary":"Keras: tar extraction permits symlink-based path traversal","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","vendor":"keras","product":"keras","ecosystem":"pip","affected":["keras < 3.12.3","keras >= 3.13.0, < 3.15.0"],"patched":["keras 3.12.3","keras 3.15.0"],"published":"2026-07-14","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-58hv-7753-xmfq","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12482"},{"url":"https://github.com/keras-team/keras/pull/23015"},{"url":"https://github.com/keras-team/keras/pull/23165"},{"url":"https://github.com/keras-team/keras/commit/9867df45c456dd1077a6243bb56219f66e288150"},{"url":"https://github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedf"},{"url":"https://github.com/keras-team/keras"},{"url":"https://github.com/keras-team/keras/releases/tag/v3.12.3"},{"url":"https://github.com/keras-team/keras/releases/tag/v3.15.0"},{"url":"https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e"}],"tags":["osv","pip"],"epss":0.00238,"epssPercentile":0.15114,"ingestedAt":"2026-08-08T19:14:53.895Z","slug":"CVE-2026-12482","body":"## Overview\n\nA vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.\n\n## Affected packages\n\n- `keras < 3.12.3`\n- `keras >= 3.13.0, < 3.15.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `keras 3.12.3`\n- `keras 3.15.0`","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}