A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-49655, has been identified in the Keras machine learning framework, specifically affecting versions 3.11.0 up to but not including 3.11.3. The flaw arises from unsafe deserialization of untrusted data within the TorchModuleWrapper class, which can be exploited when a maliciously crafted Keras file is loaded. This vulnerability allows attackers to execute arbitrary code on the victim's system, even if Keras is running in safe mode, significantly increasing the risk profile for users who routinely load external or shared model files. The issue can be triggered through both local and remote files, making it exploitable in a variety of deployment scenarios, including cloud-based and on-premises environments. The vulnerability has been assigned a CVSS v3.1 base score of 9.8, categorizing it as critical due to the ease of exploitation and the potential impact. Security researchers have highlighted that the attack does not require authentication, and exploitation can occur simply by loading a malicious model file. The vulnerability was publicly disclosed in October 2025, with security advisories urging immediate action. At the time of disclosure, the affected product versions were clearly identified, but some databases had not yet listed all impacted vendors or products. The Keras development team has released a patch in version 3.11.3 to address the issue, and users are strongly advised to upgrade to this version or later. Organizations using Keras in production or research environments should audit their model loading workflows and restrict the use of untrusted model files. The vulnerability underscores the broader risks associated with deserialization flaws in machine learning frameworks, which are increasingly targeted due to their widespread adoption. Security teams are encouraged to monitor for suspicious activity related to model file handling and to implement additional controls where feasible. The incident has prompted renewed calls for secure coding practices and rigorous input validation in AI and machine learning software. The rapid response from the Keras maintainers has been noted, but the incident serves as a warning for similar frameworks to review their own deserialization logic. The vulnerability's critical rating reflects both the technical severity and the potential for widespread exploitation if left unaddressed. Industry experts recommend that all organizations using Keras review their current deployments and apply the necessary updates without delay. The disclosure of CVE-2025-49655 has also led to increased scrutiny of third-party model sharing platforms, which may inadvertently distribute malicious files. This event highlights the importance of maintaining up-to-date software and following best practices for secure machine learning operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Advisories recommended updating Keras to a version later than 3.11.3 and avoiding untrusted Keras files as mitigation for CVE-2025-49655. References to a Keras GitHub pull request and a HiddenLayer security advisory indicate a fix and coordinated remediation guidance were available.
A critical deserialization vulnerability in Keras, tracked as CVE-2025-49655, was disclosed affecting versions 3.11.0 through 3.11.2. The flaw allows arbitrary code execution when a malicious Keras file containing a TorchModuleWrapper class is loaded, even with safe mode enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.