CVE-2026-1462Disclosure(keras / keras)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keras
  • openshift_ai

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
kerasopenshift_ai

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-13: 3Technical Details · 2026-04-13: 304-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1462 Arbitrary Code Execution in Keras 3.13.0 TFSMLayer Deserialization Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1462 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text reports a newly disclosed CVE-2026-1462 that allows arbitrary code execution through a deserialization bypass in Keras 3.13.0, but it does not mention any PoC, exploit code, active exploitation, patch, or false‑positive claim.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1462: HIGH] Critical security flaw in `keras` package v3.13.0 found: `TFSMLayer` vulnerability bypasses `safe_mode` leading to arbitrary code execution during model inference. Take precaution!#cve,CVE-2026-1462,#cybersecurity https://cvefind.com/CVE-2026-1462

    Post summary

    The tweet announces CVE‑2026‑1462 as a critical flaw in Keras v3.13.0 that allows arbitrary code execution by bypassing safe_mode during model inference.

    0000040
    620 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1462 A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization o… https://www.cve.org/CVERecord?id=CVE-2026-1462

    Post summary

    The post announces CVE-2026-1462, a deserialization vulnerability in keras's TFSMLayer that permits attacker-controlled TensorFlow SavedModels to be loaded, but it provides no evidence of exploitation, PoC, or patch.

    0000059
    57.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkeraskeras3.13.0--
Appredhatopenshift_ai---

Explore more