A vulnerability has been found in Google Keras up to 3.10.0 and classified as problematic. This vulnerability affects the function
Model.load_model
. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-8747. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.