Keras: tar extraction permits symlink-based path traversal (CVE-2026-12482)
Keras versions prior to 3.12.3 and some earlier versions contain a vulnerability in tar archive extraction that allows symlink-based path traversal. The flaw arises because symlink entries in tar archives bypass the path validation that regular files undergo, enabling attackers to create symlinks outside the intended extraction directory. This can lead to unauthorized file reads, overwrites, or directory escapes. The issue is particularly relevant for Python 3.10 and 3.11 environments where the vulnerable function is the primary defense against such attacks. The vulnerability has a low severity score and a patch is available.
AI Analysis
Technical Summary
The vulnerability in keras-team/keras version 3.12.0 arises from insufficient validation of symlink entries in tar archives during extraction. The function filter_safe_tarinfos in keras/src/utils/file_utils.py does not apply the is_path_in_dir check to symlink entries, enabling attackers to create symlinks that point outside the extraction directory. This can result in symlink-based file read, overwrite, or directory escape attacks. The vulnerability is particularly relevant for Python 3.10 and 3.11 environments where filter_safe_tarinfos is the sole protection against tar path traversal. This issue is distinct from other known Keras vulnerabilities such as CVE-2025-12060. The vulnerability has a CVSS 3.1 score of 6.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), indicating network attack vector, low complexity, no privileges or user interaction required, and impacts confidentiality and integrity but not availability. Multiple Keras versions are affected, including =1.0.7-2, =2.1.1-1, =2.2.4-1, all versions before 3.12.3, and versions from 3.13.0 up to but not including 3.15.0. A patch is available to fix this vulnerability.
Potential Impact
An attacker can craft malicious tar archives that exploit the insufficient validation of symlink entries to perform file read or overwrite operations outside the intended extraction directory. This can lead to unauthorized disclosure of files or modification of files on the system where the archive is extracted. The vulnerability affects confidentiality and integrity but does not impact availability. It requires no privileges or user interaction and can be exploited remotely via network vectors.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade affected Keras versions to 3.12.3 or later, or to versions 3.15.0 and above where the issue is fixed. Applying the official patch will ensure that symlink entries are properly validated to prevent directory traversal attacks. No additional mitigations are indicated by the vendor advisory.
Keras: tar extraction permits symlink-based path traversal (CVE-2026-12482)
Description
Keras versions prior to 3.12.3 and some earlier versions contain a vulnerability in tar archive extraction that allows symlink-based path traversal. The flaw arises because symlink entries in tar archives bypass the path validation that regular files undergo, enabling attackers to create symlinks outside the intended extraction directory. This can lead to unauthorized file reads, overwrites, or directory escapes. The issue is particularly relevant for Python 3.10 and 3.11 environments where the vulnerable function is the primary defense against such attacks. The vulnerability has a low severity score and a patch is available.
CVSS v3.0
Score 3.1low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in keras-team/keras version 3.12.0 arises from insufficient validation of symlink entries in tar archives during extraction. The function filter_safe_tarinfos in keras/src/utils/file_utils.py does not apply the is_path_in_dir check to symlink entries, enabling attackers to create symlinks that point outside the extraction directory. This can result in symlink-based file read, overwrite, or directory escape attacks. The vulnerability is particularly relevant for Python 3.10 and 3.11 environments where filter_safe_tarinfos is the sole protection against tar path traversal. This issue is distinct from other known Keras vulnerabilities such as CVE-2025-12060. The vulnerability has a CVSS 3.1 score of 6.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), indicating network attack vector, low complexity, no privileges or user interaction required, and impacts confidentiality and integrity but not availability. Multiple Keras versions are affected, including =1.0.7-2, =2.1.1-1, =2.2.4-1, all versions before 3.12.3, and versions from 3.13.0 up to but not including 3.15.0. A patch is available to fix this vulnerability.
Potential Impact
An attacker can craft malicious tar archives that exploit the insufficient validation of symlink entries to perform file read or overwrite operations outside the intended extraction directory. This can lead to unauthorized disclosure of files or modification of files on the system where the archive is extracted. The vulnerability affects confidentiality and integrity but does not impact availability. It requires no privileges or user interaction and can be exploited remotely via network vectors.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade affected Keras versions to 3.12.3 or later, or to versions 3.15.0 and above where the issue is fixed. Applying the official patch will ensure that symlink entries are properly validated to prevent directory traversal attacks. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-12482
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:18.04:LTS","Ubuntu:20.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.0
Threat ID: 6a58b4f968715ace43db2204
Added to database: 07/16/2026, 10:39:53 UTC
Last enriched: 08/08/2026, 17:01:25 UTC
Last updated: 08/27/2026, 10:52:07 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.