Executive brief
MONAI is a machine learning framework for medical imaging used by researchers and hospitals. Versions before 1.6.0 allow attackers to execute arbitrary code by crafting malicious .npy or .npz files that get loaded through MONAI's standard data pipeline. An attacker could poison shared datasets or tutorials to gain control of any machine running MONAI, potentially compromising sensitive patient data and hospital systems.
Technical details
The NumpyReader class unconditionally calls numpy.load() with allow_pickle=True when reading .npy and .npz files, enabling arbitrary code execution via pickle deserialization. The vulnerability affects the entire MONAI data pipeline (LoadImage, PersistentDataset, CacheDataset, SmartCacheDataset) and the allow_pickle parameter is hardcoded and cannot be overridden by users. An attacker with the ability to control input .npy files can execute arbitrary code with the privileges of the MONAI process.
Affected products
- Project-MONAI MONAI before 1.6.0
Timeline
- 2026-06-11: disclosed
- 2026-09-26: advisory
- 2026-09-27: patched: Version 1.6.0 released