Executive brief
MONAI is a deep learning framework for medical imaging used to load and execute pre-trained model bundles. The bundle configuration engine allows arbitrary Python code execution through two mechanisms: unvalidated _target_ values resolved to any importable function, and $ expressions passed directly to eval(). An attacker can publish a malicious bundle that executes arbitrary code when a victim loads it using monai.bundle.load() or monai.bundle.run().
Technical details
The vulnerability exists in MONAI's configuration parser, which resolves _target_ values via locate() without an allowlist and passes $ expressions to eval() without sanitization. These sinks are reachable from monai.bundle.load() (which downloads bundles and parses configs) and monai.bundle.run(), triggered when the network definition is instantiated. Exploitation requires user interaction (loading a bundle) but grants full code execution in the loading process; no patches are available as of the advisory date.
Affected products
- Project-MONAI MONAI through 1.6.0
Timeline
- 2026-08-21: disclosed
- 2026-09-27: advisory