A vulnerability in the open source deep learning tool Keras could allow attackers to load arbitrary local files or conduct SSRF attacks.
Competition shows it is possible to discover and patch vulnerabilities in open-source programs without human aid.