PT-2026-105782 · Pypi · Monai

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo from pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo from pickle on an attacker-supplied pickle file, an object defining reduce is executed during deserialization, resulting in arbitrary code execution in the context of the application.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4021

Affected Products

Monai