Deserialization of Untrusted Data in Keras - CVE-2025-49655
Published: November 25, 2025
Vulnerability identifier: #VU118764
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49655
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data while parsing external modules. A remote attacker can trick the victim into loading a malicious module and execute arbitrary code on the target system.
Affected software
Keras
Trusted Artifact Signer (RHTAS)
Red Hat OpenShift AI (RHOAI)
Trusted Artifact Signer (RHTAS)
Red Hat OpenShift AI (RHOAI)
How to mitigate CVE-2025-49655
Install updates from vendor's website.
Keras - update to 3.11.3
Trusted Artifact Signer (RHTAS) - update to 1.3.1
Red Hat OpenShift AI (RHOAI) - update to 2.25.1
Trusted Artifact Signer (RHTAS) - update to 1.3.1
Red Hat OpenShift AI (RHOAI) - update to 2.25.1