PT-2026-99460 · Monai · Monai

·

CVE-2026-100840

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MONAI versions prior to 1.6.1
Description The bundle configuration engine allows remote code execution because it resolves target values to arbitrary importable callables without using an allow list and passes $ expressions to the Python eval() function. An attacker can publish a malicious bundle with a crafted configuration containing arbitrary code that executes when a victim uses the monai.bundle.load() or monai.bundle.run() functions.
Recommendations Update to version 1.6.1 or later. As a temporary mitigation, avoid using the monai.bundle.load() and monai.bundle.run() functions with bundles from untrusted sources.

Exploit

Fix

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100840
GHSA-873F-PVRV-4X83

Affected Products

Monai