CVE-2026-9335 is an arbitrary local file content disclosure vulnerability in keras-team/keras versions up to and including 3.14.0. The issue arises from improper handling of HDF5 ExternalLinks in the KerasFileEditor and keras.saving.load_weights code paths. Although Keras includes helper routines intended to reject unsafe HDF5 link types such as ExternalLinks and SoftLinks, these functions bypass those protections and allow automatic dereferencing of linked external HDF5 objects. As a result, a crafted model, weights, or Keras archive file can cause Keras to read attributes and datasets from attacker-referenced local HDF5 files on the victim system. In KerasFileEditor, linked content is extracted into internal structures, and in keras.saving.load_weights, linked data is loaded into the target model.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
.h5, .weights.h5, or .keras file can cause Keras to dereference external links and expose contents from local files without the user's intent. The primary impact is unauthorized read access to local file content, which may include model data, proprietary datasets, or other sensitive information stored in HDF5 format.If you can’t patch tonight, do this now.
.h5, .weights.h5, or .keras files with affected Keras versions. Restrict ingestion of externally supplied model and weight artifacts, especially in automated pipelines. Where possible, validate or sanitize HDF5 content before processing to reject ExternalLinks and SoftLinks, and isolate model-loading workflows from sensitive local data to reduce disclosure risk.Patch, then assume compromise.
KerasFileEditor and keras.saving.load_weights consistently use helper logic that rejects HDF5 ExternalLinks and SoftLinks rather than dereferencing them automatically.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python proof-of-concept repository for CVE-2026-9335, not a framework module. It contains two executable PoCs, pinned reproduction requirements, a technical advisory, disclosure timeline, README, license, and gitignore. The vulnerability is a local malicious-file attack against Keras <= 3.14.0: KerasFileEditor and the legacy .h5/.hdf5 load_weights branch directly index HDF5 members without first checking their link type. h5py dereferences ExternalLink objects during indexing, allowing an attacker-controlled HDF5 artifact to redirect Keras to another locally readable HDF5 file. poc/poc_file_editor.py demonstrates disclosure of a linked group's dataset bytes and attributes via KerasFileEditor. poc/poc_load_weights.py demonstrates a model_weights link to a separate HDF5 file, resulting in victim weights being loaded into the user's model. Both PoCs create only temporary local attacker/victim files, print confirmation on success, and attempt cleanup. No network communication, remote C2, shell execution, persistence, or destructive behavior is present. The included documentation states the issue is fixed in Keras 3.15.0 by rejecting ExternalLink and SoftLink objects before indexing.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.