CVE-2026-1462
keras-team keras-team/keras, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3 취약점
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.40% 백분위 33.3% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.14