Executive brief
MONAI is a medical imaging AI library used for automated 3D segmentation analysis. The algo_from_pickle function loads algorithm objects from pickle files without validation, allowing an attacker to craft a malicious pickle file that executes arbitrary code when loaded. An application using this function to process untrusted pickle files could be compromised with full system access.
Technical details
The algo_from_pickle function in monai/auto3dseg/utils.py deserializes pickle data via pickle.loads() without validating input, enabling arbitrary code execution through __reduce__ gadgets. An attacker must supply a malicious .pkl file and the application must invoke algo_from_pickle on it; the exploit runs in the application's security context. A fix is available in MONAI 1.5.2.
Affected products
- Project-MONAI MONAI before 1.5.2
Timeline
- 2026-09-27: disclosed
- 2026-04-03: patched: Version 1.5.2 released