PT-2026-105782 · Pypi · Monai
Published
2026-09-27
·
Updated
2026-09-27
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo from pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo from pickle on an attacker-supplied pickle file, an object defining reduce is executed during deserialization, resulting in arbitrary code execution in the context of the application.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Monai