GPU VulnDB

Database/AI/ML frameworks & serving

Keras (`utils.get_file`, tar extract): Path traversal on tar extraction

CVE-2025-12060AI/ML frameworks & servingcurated

Impact

Path traversal on tar extraction → arbitrary file write

Who can reach it

Customer-supplied dataset/model URL fetched with extract=True

What to do

Upgrade; a training job with write access to shared mounts can escape into other tenants' paths if mounts are shared

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.