CVE-2026-12481Disclosure(keras / keras)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), bypassing the guard and allowing attacker-controlled `marshal` bytecode to be deserialized. Affected call sites include `keras.layers.deserialize(config)`, `keras.models.clone_model(model)`, and any direct invocation of `Lambda.from_config(config)` without an enclosing `SafeModeScope(True)`. This vulnerability can be exploited to achieve arbitrary OS-level code execution in the context of the server or user process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keras

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-03); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
keras

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-03: 2Mentions · 2026-07-10: 1Mentions · 2026-07-28: 1Technical Details · 2026-07-03: 2Technical Details · 2026-07-10: 1Technical Details · 2026-07-28: 107-0307-1007-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-032
Disclosure2
2026-07-101
Disclosure1
2026-07-281
Disclosure1
Full discourse4 posts
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    脆弱性対応ウォッチ、本日更新しました。新たにCVE-2026-12481(keras Lambda逆シリアライズRCE)の情報を追加しています。関係者の方は、ぜひ早めの情報確認と対策をご検討ください。 https://cve.autoarticles.net/cve/CVE-2026-12481

    Post summary

    A new CVE-2026-12481, a Keras Lambda deserialization RCE, has been added to the vulnerability watch list, urging stakeholders to review information and consider mitigation.

    0000054
    561 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🧠 CVE-2026-12481: Critical RCE (CVSS 9.8) in Keras 3.14.0. Deserializing an untrusted model with a `Lambda` layer can execute arbitrary code. Watch what your ML pipelines load. #MLSecurity #AppSec https://secalerts.co/vulnerability/CVE-2026-12481?utm_campaign=x https://t.co/dy12YFQL2z

    Post summary

    Disclosed a critical remote code execution vulnerability (CVSS 9.8) in Keras 3.14.0 allowing arbitrary code execution via untrusted model deserialization with Lambda layers.

    0000099
    855 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12481 A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically… https://www.cve.org/CVERecord?id=CVE-2026-12481 ----- Traducción: CVE-2026-12481 Una… http://infoflow.cloud`

    Post summary

    The post announces a newly disclosed CVE (CVE-2026-12481) that permits arbitrary code execution in Keras 3.14.0 via deserialization issues in the Lambda layer, including a CVE reference link and a brief translation.

    0000035
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12481 A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically… https://www.cve.org/CVERecord?id=CVE-2026-12481

    Post summary

    The text announces CVE-2026-12481, a newly disclosed arbitrary code execution vulnerability in Keras 3.14.0 caused by deserialization handling in the Lambda layer, without mentioning exploits, patches, or active use.

    00000655
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkeraskeras3.14.0--

Explore more