CVE-2024-55459: Keras

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

Affected products

  • Keras Keras: version 3.7.0 only

Published 2025-01-08. Last modified 2026-06-17.