CVE-2026-1669Disclosure(keras / keras)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keras

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
keras

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 102-1102-1702-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Giuseppe `N3mes1s`@N3mes1s
    Disclosure

    First #Pruva CVE assigned today in Keras. CVE-2026-1669 - Local File Disclosure via HDF5 External Storage During Keras Weight Loading - https://github.com/keras-team/keras/security/advisories/GHSA-3m4q-jmj6-r34q - https://www.cve.org/CVERecord?id=CVE-2026-1669 Not only hashtag#pruva is capable to reproduce, but even doing hyphotesis generation and reproduce them to make sure they are really vulnerabilities or not. And the way to trigger it and read the leaked content is even funnier.

    Post summary

    The post announces the assignment of CVE-2026-1669 to Keras, linking to the official advisory and CVE record, and notes that the vulnerability allows local file disclosure during weight loading.

    000401.0K
    12.8K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-1669: Model Poisoning: Turning Keras Weights into Weaponized File Readers A high-severity Arbitrary File Read vulnerability in the Keras machine learning library allows attackers to exfiltrate sensitive local files (like /etc/passwd or AWS cr... https://cvereports.com/reports/CVE-2026-1669

    Post summary

    The text announces a new high‑severity arbitrary file read vulnerability in Keras (CVE‑2026‑1669) without providing a PoC, exploit code, or patch details.

    0000049
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1669 Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read… https://www.cve.org/CVERecord?id=CVE-2026-1669

    Post summary

    The statement announces CVE‑2026‑1669, describing an arbitrary file read vulnerability in Keras’s HDF5 model loading, but provides no evidence of PoC, exploitation, or patch.

    00000194
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkeraskeras---

Explore more