CVE-2025-12060 Security Alert: HIGH Vulnerability
Urgent: CVE-2025-12060 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical vulnerability (CVE-2025-12060) has been identified in Keras's keras.utils.get_file() function, allowing directory traversal attacks. This high-severity issue (CVSS 9.8) can potentially let attackers write files outside the intended extraction directory by exploiting a flaw in the tarfile extraction process. Solo developers and small teams using Keras for machine learning projects are urged to take immediate action to protect their systems.
Immediate Action
- Review and update Keras to a patched version as soon as it is available.
- Temporarily disable any automated dataset fetching that uses
keras.utils.get_file()until a fix is applied. - Monitor your systems for unauthorized file writes that may indicate exploitation attempts.
- Implement strict access controls on directories where Keras datasets are extracted.
- Stay informed via the Keras official channels for updates on this vulnerability.
Affected Versions
keras@<=2.13.0vulnerable; upgrade to2.13.1+tensorflow.keras@<=2.13.0vulnerable; upgrade to2.13.1+
Resolution Guide
To mitigate this vulnerability, follow these commands based on your environment:
pip install --upgrade keras==2.13.1
pip install --upgrade tensorflow==2.13.1
For a code fix, ensure that the extraction method includes the proper filtering parameter:
archive.extractall(path, members=filter_safe_paths(archive), filter="data")
Detection & Verification
To check if your version of Keras is vulnerable, run:
pip show keras
To verify the fix after updating, check the version again with the same command and ensure it reflects the patched version.
Risk and Impact
The exploitation of this vulnerability can lead to arbitrary file writes on the target system, potentially compromising sensitive files or configurations. The blast radius includes any applications relying on Keras for downloading datasets, making it critical for developers to act swiftly to mitigate risks.
```