Skip to content

Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

High severity GitHub Reviewed Published Sep 19, 2025 to the GitHub Advisory Database • Updated Sep 19, 2025
Withdrawn This advisory was withdrawn on Sep 19, 2025

No open alerts for this advisory

Give feedback on Dependabot alerts