Skip to content

[GHSA-48g7-3x6r-xfhp] Arbitrary Code Execution via Crafted Keras Config for Model Loading#7212

Closed
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-7212from
decsecre583:patch-3
Closed

[GHSA-48g7-3x6r-xfhp] Arbitrary Code Execution via Crafted Keras Config for Model Loading#7212
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-7212from
decsecre583:patch-3

Conversation

@decsecre583
Copy link

Updates

  • references

Comments

  • Add a patch commit keras-team/keras@179ebeb: This commit on the mlx branch contains similar code changes to the existing advisory patch e67ac8f, specifically in keras/src/models/functional.py (lines 527–531) and keras/src/saving/serialization_lib.py (lines 786–798), both adding checks to deserialization. This indicates it is the corresponding security fix for CVE-2025-1550 on the mlx branch.

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-7212 March 22, 2026 18:45
@helixplant
Copy link

Hi,
Thanks for the contribution. The GHSA already includes a confirmed patch commit, so this mlx branch commit appears to be parallel/similar code rather than a distinct fix. As a result, it doesn’t add additional reference value beyond what the existing patch commit already provides.

@helixplant helixplant closed this Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants