logo

Zscaler Discovers Vulnerability in Keras Models Allowing Arbitrary File Access and SSRF (CVE-2025-12058)

ID: 315fb5b1-276a-58d5-8dc9-afb7160657a2

STIX ID: report--315fb5b1-276a-58d5-8dc9-afb7160657a2

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-11-04

Date Updated: 2026-05-01

...
...

This report outlines attack scenarios in which malicious pre-trained ML models (for example, .keras models using StringLookup vocabularies) are used to read and exfiltrate local files and cloud metadata—such as SSH private keys, .gitconfig/.netrc credentials, and AWS/GCP/Azure IAM tokens—when loaded by developers, CI systems, or cloud instances, enabling supply-chain compromise, repository takeover, and full cloud infrastructure access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.