CVE-2024-3660
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2024-3660, https://github.com/keras-team/keras, https://github.com/keras-team/keras/compare/r2.12...r2.13, https://kb.cert.org/vuls/id/253266, https://www.kb.cert.org/vuls/id/253266, https://pypi.org/project/keras, https://github.com/advisories/GHSA-x4wf-678h-2pmq