Sceawere

Vulnerability Detail

CVE-2026-100840UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MONAI Bundle Remote Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Project-MONAI
Product
MONAI
Attack Type
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-27T02:17:22.387Z",
  "pubdate": "2026-09-27T02:17:22.387Z",
  "executiveSummary": "MONAI versions through 1.6.0 contain a critical remote code execution (RCE) vulnerability within its bundle configuration engine.\nThe vulnerability arises from insecure deserialization and dynamic evaluation of untrusted configuration files, allowing arbitrary code execution on systems that process malicious bundles.\nThe flaw affects the monai.bundle.load() and monai.bundle.run() functions, which are responsible for initializing model configurations.\nAn attacker can exploit this by distributing a crafted bundle containing malicious directives that trigger execution upon ingestion.\nThe risk is severe as it grants an attacker the ability to execute arbitrary Python code with the privileges of the user running the MONAI application.\nThis vulnerability does not require authentication to trigger; however, it necessitates user interaction or automated ingestion of a compromised bundle file.\nOrganizations relying on MONAI for medical imaging workflows should prioritize updating to a remediated version or restricting bundle sourcing to trusted, internal repositories.",
  "technicalDetails": "The vulnerability resides in the MONAI bundle configuration engine, specifically in the mechanisms used to resolve dynamic components within configuration files.\nThe configuration engine permits the use of '_target_' keys, which are intended to map configuration parameters to importable Python callables. In versions 1.6.0 and earlier, this resolution process lacks an allow-list, meaning the engine can resolve any class or function accessible within the Python path, regardless of its safety or intended use.\nFurthermore, the engine supports a '$' prefix syntax within configuration values to denote dynamic evaluation. The library processes these expressions by passing them directly to the Python 'eval()' function without sufficient sanitization or isolation.\nAn attack flow commences when a victim invokes 'monai.bundle.load()' or 'monai.bundle.run()' on an untrusted bundle. The engine parses the 'config.json' or associated YAML files within the bundle. When the parser encounters a '$' expression, it initiates the 'eval()' call, executing the embedded arbitrary Python code.\nSimultaneously, by manipulating the '_target_' parameter, an attacker can instantiate arbitrary Python objects, leading to gadget-based exploitation scenarios. By chaining these capabilities, an attacker can achieve a full remote code execution payload that executes in the context of the host process.\nThe vulnerability is inherent to the design of the configuration loader. Because 'eval()' is invoked on user-controlled input, there is no validation of the code's source or intent. The lack of an allow-list for '_target_' imports effectively bypasses intended sandboxing, granting the attacker the ability to import system-level modules (e.g., 'os', 'subprocess') to facilitate further malicious activity, such as reverse shell spawning, file exfiltration, or persistence.\nThis is a client-side or server-side processing vulnerability depending on the deployment; any automated pipeline that fetches and executes bundles from external, untrusted, or unauthenticated sources is at immediate risk. The impact is total system compromise relative to the local execution environment, as there are no inherent privilege restrictions enforced by the MONAI engine during the configuration resolution phase."
}
CVE-2026-100840: MONAI Bundle Remote Code Execution (HIGH Severity, CVSS: 7.8) | Sceawere