Executive brief
MONAI is a medical imaging AI framework that caches processed data locally to improve performance. A flaw in how MONAI handles cached data allows any local user who can write to the cache directory (common on shared systems like HPC clusters) to insert malicious files that execute arbitrary code when another user's MONAI pipeline reads the cache. This affects all released versions with no patch available.
Technical details
The vulnerability stems from PersistentDataset forcing weights_only=False in torch.load() when caching MetaTensors, combined with monai/data/utils.py using pickle.loads() to deserialize cached content and MD5 hashing for cache keys. An attacker with local write access to a shared cache directory can place a malicious pickle file that gets deserialized without validation, achieving arbitrary code execution in the victim's process context. No patched version exists as of the advisory date.
Affected products
- Project-MONAI MONAI all released versions (0 and higher)
Timeline
- 2026-08-21: disclosed: GitHub security advisory GHSA-636w-j999-g7x5 published
- 2026-09-27: advisory: CVE-2026-100841 assigned