GHSA-gfmx-qqqh-f38q

Suggest an improvement
Source
https://github.com/advisories/GHSA-gfmx-qqqh-f38q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gfmx-qqqh-f38q/GHSA-gfmx-qqqh-f38q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gfmx-qqqh-f38q
Downstream
CGA (2)
MINI (1)
Withdrawn
2026-02-18T22:38:48Z
Published
2026-02-12T00:31:03Z
Modified
2026-09-10T03:50:35Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Duplicate Advisory: Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-3m4q-jmj6-r34q. This link is maintained to preserve external references.

Original Description

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

Database specific
{
    "cwe_ids":  [
        "CWE-73"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-12T22:09:52Z",
    "nvd_published_at":  "2026-02-11T23:16:03Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / keras

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Last Affected
3.13.1

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.1.0
3.1.1
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.8.0
3.9.0
3.9.1
3.9.2
3.10.0
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-gfmx-qqqh-f38q/GHSA-gfmx-qqqh-f38q.json"