PT-2026-99463 · Monai · Monai
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MONAI versions prior to 1.6.0
Description
Remote code execution is possible through the
algo from pickle() function in monai/auto3dseg/utils.py. The issue stems from the unsafe use of pickle.loads() during deserialization, which allows attackers to execute arbitrary system commands by providing specially crafted pickle files.Recommendations
Update to version 1.6.0 or later.
As a temporary workaround, avoid using the
algo from pickle() function when processing untrusted files.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Monai