PT-2026-99460 · Monai · Monai
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MONAI versions prior to 1.6.1
Description
The bundle configuration engine allows remote code execution because it resolves
target values to arbitrary importable callables without using an allow list and passes $ expressions to the Python eval() function. An attacker can publish a malicious bundle with a crafted configuration containing arbitrary code that executes when a victim uses the monai.bundle.load() or monai.bundle.run() functions.Recommendations
Update to version 1.6.1 or later.
As a temporary mitigation, avoid using the
monai.bundle.load() and monai.bundle.run() functions with bundles from untrusted sources.Exploit
Fix
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Monai