Vulnerability Description
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Keras | Keras | 3.12.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6eExploitThird Party Advisory
- https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6eExploitThird Party Advisory
FAQ
What is CVE-2026-12482?
CVE-2026-12482 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifica...
How severe is CVE-2026-12482?
CVE-2026-12482 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12482?
Check the references section above for vendor advisories and patch information. Affected products include: Keras Keras.