Zscaler Discovers Vulnerability in Keras Models Allowing Arbitrary File Access and SSRF (CVE-2025-12058)
ID: 315fb5b1-276a-58d5-8dc9-afb7160657a2
STIX ID: report--315fb5b1-276a-58d5-8dc9-afb7160657a2
Feed Name: Zscaler Security Research Blog
Threat Score
This report outlines attack scenarios in which malicious pre-trained ML models (for example, .keras models using StringLookup vocabularies) are used to read and exfiltrate local files and cloud metadata—such as SSH private keys, .gitconfig/.netrc credentials, and AWS/GCP/Azure IAM tokens—when loaded by developers, CI systems, or cloud instances, enabling supply-chain compromise, repository takeover, and full cloud infrastructure access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
