Cooperate with Dingyu Wang and Jianhe Li
keras-preprocessing R/W: Path Traversal & Symlink Attacks (5 Verified Findings)
Repository: https://github.com/keras-team/keras-preprocessing Affected: keras-preprocessing <=1.1.0 Severity: High (Arbitrary File Read / Write outside dataset root)
Overview
Five independent path traversal and symlink-related vulnerabilities discovered in keras-preprocessing's image data loading pipeline (ImageDataGenerator). All findings have been verified with runtime PoC output.
Finding List
| ID | Vulnerability | Entry Point | CWE |
|---|---|---|---|
| RW-01 | flow_from_dataframe() path traversal read |
ImageDataGenerator.flow_from_dataframe() |
CWE-22 |
| RW-02 | save_prefix arbitrary write via traversal |
flow() / flow_from_directory() / flow_from_dataframe() |
CWE-22 |
| RW-03 | Symlinked file read inside dataset tree | ImageDataGenerator.flow_from_directory() |
CWE-22 |
| RW-04 | Directory symlink traversal (follow_links=True) |
flow_from_directory(follow_links=True) |
CWE-22 |
| RW-05 | Directory symlink traversal v2 (follow_links=True) |
flow_from_directory(follow_links=True) |
CWE-22 |
Quick Start
pip install keras-preprocessing==1.1.0 Pillow numpy pandas
python poc_rw01.py # Path traversal read
python poc_rw02.py # Arbitrary write
python poc_rw03.py # Symlink read
python poc_rw04.py # Directory traversal (follow_links=True)
python poc_rw05.py # Directory traversal v2 (follow_links=True)
Root Cause Summary
Each PoC demonstrates that os.path.join() + image loading utilities in keras_preprocessing/image/ can be escaped via path traversal (../) or symlink abuse because no realpath()/normpath() containment check is applied after path construction.
Affected Source Files
keras_preprocessing/image/dataframe_iterator.pykeras_preprocessing/image/iterator.pykeras_preprocessing/image/directory_iterator.pykeras_preprocessing/image/utils.py
Verifications
All 5 findings verified with runtime marker output on keras-preprocessing 1.1.0. See output_rw0*.txt files for full runtime evidence.