A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the same `is_path_in_dir` validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where `filter_safe_tarinfos` is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.
References
Configurations
No configuration.
History
14 Jul 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://huntr.com/bounties/5d3638e8-a9f6-4964-a865-ddb9fe4d4b6e - |
14 Jul 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 06:16
Updated : 2026-07-15 20:56
NVD link : CVE-2026-12482
Mitre link : CVE-2026-12482
CVE.ORG link : CVE-2026-12482
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
