Junglewise Threat Intelligence

CVE-2025-58755: Project-MONAI MONAI path traversal in ZIP extraction

CVE-2025-58755 · Severity: high · CVSS 8.8 · Published 2025-09-09

Technologies: monai (PyPI), Project-MONAI MONAI. Vendors: PyPI, Project-MONAI.

Executive brief

MONAI, a framework for deep learning in healthcare imaging, is vulnerable to a security flaw when processing compressed files. An attacker can create a specially crafted ZIP file that, when downloaded and extracted by the software, overwrites critical system files or configuration data. This could lead to a complete system takeover, data loss, or the inability to boot the affected computer.

Technical details

A path traversal vulnerability exists in MONAI due to the insecure use of the 'zip_file.extractall()' function. The software fails to validate that the file paths contained within a ZIP archive remain within the intended destination directory. An attacker can exploit this by providing a malicious ZIP file containing filenames with traversal sequences (e.g., '../../'). When a user utilizes the 'monai.bundle.scripts.download' function or other extraction utilities to process such a file, the application will write files to arbitrary locations on the filesystem. This can be used to overwrite sensitive files like '/etc/passwd' or SSH keys. The vulnerability is patched in version 1.5.1.

Affected products

  • Project-MONAI monai <= 1.5.0

Timeline

  • 2025-09-08: disclosed
  • 2025-09-09: advisory
  • 2025-09-09: patched

References

Related threats