Junglewise Threat Intelligence

CVE-2026-100843: MONAI remote code execution in algo_from_pickle

CVE-2026-100843 · Severity: high · CVSS 7.8 · Published 2026-09-27

Technologies: Project-MONAI MONAI. Vendors: Project-MONAI.

Executive brief

MONAI is a medical imaging framework used in AI-powered diagnostic and analysis workflows. Versions before 1.6.0 contain a flaw that allows attackers to execute arbitrary system commands when processing specially crafted model files, potentially giving an attacker complete control over systems running MONAI pipelines. This is particularly dangerous in healthcare settings where model checkpoints are frequently exchanged between organizations.

Technical details

The vulnerability stems from unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py's algo_from_pickle() function, which deserializes untrusted pickle data without validation. An attacker can craft a malicious pickle file that executes arbitrary code during deserialization. The vulnerability requires local access and user interaction (supply of a file path), but grants full system command execution with the privileges of the process running MONAI.

Affected products

  • Project-MONAI MONAI before 1.6.0

Timeline

  • 2026-06-11: disclosed: GHSA-qxq5-qhx6-94qw published; incomplete fix discovery
  • 2026-01-29: patched: Version 1.6.0 released with complete fix
  • 2026-09-27: advisory: CVE-2026-100843 published

References

Related threats