project-monai

7 records · 7 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names project-monai as an affected vendor, highest CVSS first.

  1. HIGH 8.4CVE-2026-100844public PoC

    MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatena…

    monai

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.8CVE-2026-100845public PoC

    MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execut…

    monai

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.8CVE-2026-100843public PoC

    MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system comm…

    monai

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.8CVE-2026-100841public PoC

    In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). …

    monai

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.8CVE-2026-100840public PoC

    MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malic…

    monai

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.6CVE-2026-100846public PoC

    MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If…

    monai

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7CVE-2026-100842public PoC

    MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' …

    monai

    AI risk analysis on Exploit-DB.ai →