A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-1329 | A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application. | 
|  Github GHSA | GHSA-x4wf-678h-2pmq | Keras code injection vulnerability | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Tue, 23 Sep 2025 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Keras Keras keras | |
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:* | |
| Vendors & Products | Keras Keras keras | 
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Tensorflow Tensorflow tensorflow | |
| CPEs | cpe:2.3:a:tensorflow:tensorflow:*:*:*:*:*:*:*:* | |
| Vendors & Products | Tensorflow Tensorflow tensorflow | |
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-02-13T17:52:58.005Z
Reserved: 2024-04-11T16:41:23.481Z
Link: CVE-2024-3660
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T20:20:00.692Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-04-16T21:15:08.603
Modified: 2025-09-23T01:35:15.470
Link: CVE-2024-3660
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.