Executive brief
MONAI is a medical imaging AI framework that processes computational models and bundles. An attacker who can control a bundle's metadata configuration can inject Python code that bypasses security filters and executes arbitrary commands. This could allow an attacker to steal data, modify models, or compromise systems that use MONAI to process medical imaging bundles.
Technical details
The vulnerability is an eval injection (CWE-95) in _get_fake_spatial_shape() within monai/bundle/scripts.py. The function validates shape expressions by checking for ast.Name nodes and rejecting names outside a whitelist (p, n), but expressions using only object introspection chains like "(1).__class__.__bases__[0].__subclasses__()" bypass this filter because they contain no ast.Name nodes. An attacker with the ability to influence bundle metadata (reachable through the verify_net_in_out CLI flow) can supply such expressions to achieve code execution.
Affected products
- Project-MONAI MONAI through 1.6.0
Timeline
- 2026-09-27: disclosed