CVE-2026-11816
keras-team keras-team/keras, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI)
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD) instead of the actual extraction destination. When the process runs with CWD set to `/`, which is common in Docker containers, CI/CD runners, and Jupyter environments, the validation boundary becomes the filesystem root, allowing traversal paths to bypass the security check. Additionally, the z...
- CVSS
- 8.1
- EPSS
- 0.56% 43.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.11