Downloads · 30 days
0
rajasingh010/keras-saveable-rce
keras-saveable-rce is a machine learning model from rajasingh010. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for keras. The card lists the license as apache-2.0.
File: keras/src/saving/kerassaveable.py Function: unpicklemodel(), reduce() Type: Remote Code Execution (Insecure Deserialization)
Downloads · 30 days
0
Access
Public
Updated Apr 4, 2026
Repo size
144 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 51%
From the Hugging Face model README
File: keras/src/saving/keras_saveable.py
Function: _unpickle_model(), __reduce__()
Type: Remote Code Execution (Insecure Deserialization)
KerasSaveable.__reduce__() returns _unpickle_model which calls
_load_model_from_fileobj(safe_mode=False) with no allowlist protection.
class KerasSaveable:
def __reduce__(self):
return (_unpickle_model, (buffer,))
def _unpickle_model(buffer):
return _load_model_from_fileobj(buffer, safe_mode=False) # NO PROTECTION
When a victim calls pickle.load() on a malicious KerasSaveable pickle,
arbitrary code execution occurs through the hardcoded safe_mode=False.
import pickle
with open("malicious_keras_rce.pkl", "rb") as f:
result = pickle.load(f) # RCE triggered via __reduce__