CVE-2024-3660: Keras

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

Affected products

  • Keras Keras: before 2.13.1 (fixed in 2.13.1)

Published 2024-04-16. Last modified 2026-06-17.