CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12482

lowCVSS 3.1covered by 1 sourcefirst seen 2026-07-14
A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the filter_safe_tarinfos validation in keras/src/utils/file_utils.py. Specifically, symlink entries are not subjected to the same is_path_in_dir validation as regular file entries, allowing symlinks to be created outside the intended extraction directory. This can lead to symlink-based file read, file overwrite, or directory escape attacks. The issue is particularly impactful on Python 3.10 and 3.11, where filter_safe_tarinfos is the sole defense against tar path traversal. This vulnerability is distinct from CVE-2025-12060 and other previously reported issues.

⚡ Watch CVE-2026-12482

Get an email if CVE-2026-12482 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-12482

CVE.org record

Embed the live status

CVE-2026-12482 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12482 status](https://www.csirts.com/badge/CVE-2026-12482)](https://www.csirts.com/cve/CVE-2026-12482)