CVE-2025-12060 Security Alert: HIGH Vulnerability

Urgent: CVE-2025-12060 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical vulnerability (CVE-2025-12060) has been identified in Keras's keras.utils.get_file() function, allowing directory traversal attacks. This high-severity issue (CVSS 9.8) can potentially let attackers write files outside the intended extraction directory by exploiting a flaw in the tarfile extraction process. Solo developers and small teams using Keras for machine learning projects are urged to take immediate action to protect their systems.

Immediate Action

  • Review and update Keras to a patched version as soon as it is available.
  • Temporarily disable any automated dataset fetching that uses keras.utils.get_file() until a fix is applied.
  • Monitor your systems for unauthorized file writes that may indicate exploitation attempts.
  • Implement strict access controls on directories where Keras datasets are extracted.
  • Stay informed via the Keras official channels for updates on this vulnerability.

Affected Versions

  • keras@<=2.13.0 vulnerable; upgrade to 2.13.1+
  • tensorflow.keras@<=2.13.0 vulnerable; upgrade to 2.13.1+

Resolution Guide

To mitigate this vulnerability, follow these commands based on your environment:

pip install --upgrade keras==2.13.1
pip install --upgrade tensorflow==2.13.1

For a code fix, ensure that the extraction method includes the proper filtering parameter:

archive.extractall(path, members=filter_safe_paths(archive), filter="data")

Detection & Verification

To check if your version of Keras is vulnerable, run:

pip show keras

To verify the fix after updating, check the version again with the same command and ensure it reflects the patched version.

Risk and Impact

The exploitation of this vulnerability can lead to arbitrary file writes on the target system, potentially compromising sensitive files or configurations. The blast radius includes any applications relying on Keras for downloading datasets, making it critical for developers to act swiftly to mitigate risks.

```

Keep reading