Executive brief
Keras is a machine learning library that provides a utility function (keras.utils.get_file) for downloading and extracting datasets. When extracting TAR archives with the extract option enabled, the function is vulnerable to path traversal attacks that allow malicious archives to write files outside the intended extraction directory, potentially compromising the integrity of the system and enabling attackers to overwrite critical files.
Technical details
The vulnerability exists in Keras's extract_archive() function in keras/src/utils/file_utils.py, which uses Python's tarfile.extractall() method without the security-critical filter="data" parameter. While Keras implements filter_safe_paths() to validate tar member paths, this filtering occurs during member parsing, before extraction. However, a PATH_MAX symlink resolution bug in Python's tarfile module triggers during actual file system operations, causing excessively long symlink paths to fail resolution and be interpreted literally, bypassing the path filter. This allows attackers to craft malicious tar archives with carefully constructed symlink chains that exploit the PATH_MAX resolution issue to write files to arbitrary locations outside the intended extraction directory. The vulnerability affects all Keras versions prior to 3.12.0 and requires the attacker to provide a malicious tar archive that will be processed with extract=True.
Affected products
- Keras Team Keras <3.12.0
Timeline
- 2025-10-30: disclosed
- 2025-12-02: patched: Keras 3.12.0 fixes the vulnerability
- 2025-12-02: other: Advisory GHSA-28jp-44vh-q42h withdrawn as duplicate of GHSA-hjqc-jx6g-rwp9