
First #Pruva CVE assigned today in Keras. CVE-2026-1669 - Local File Disclosure via HDF5 External Storage During Keras Weight Loading - https://github.com/keras-team/keras/security/advisories/GHSA-3m4q-jmj6-r34q - https://www.cve.org/CVERecord?id=CVE-2026-1669 Not only hashtag#pruva is capable to reproduce, but even doing hyphotesis generation and reproduce them to make sure they are really vulnerabilities or not. And the way to trigger it and read the leaked content is even funnier.
Post summary
The post announces the assignment of CVE-2026-1669 to Keras, linking to the official advisory and CVE record, and notes that the vulnerability allows local file disclosure during weight loading.


