Sceawere
Vulnerability Detail
CVE-2026-100841UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MONAI PersistentDataset Insecure Deserialization Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Project-MONAI
- Product
- MONAI
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-27T02:17:22.543Z",
"pubdate": "2026-09-27T02:17:22.543Z",
"executiveSummary": "The MONAI framework is susceptible to an insecure deserialization vulnerability within the PersistentDataset component and associated cache utilities.\nThe vulnerability arises from the mandatory use of torch.load(weights_only=False) when handling MetaTensors, coupled with the reliance on the pickle module to deserialize cached data.\nAn attacker with write access to a shared or world-writable cache directory can inject malicious serialized objects.\nSuccessful exploitation leads to arbitrary code execution (ACE) within the security context of the user running the MONAI pipeline.\nThis impacts all released versions of the MONAI pip package. The risk is critical in multi-user environments, such as HPC clusters or shared workstations, where cache directories are not strictly isolated.\nThe exploitation does not require authentication to the application itself, as it leverages the trust model of the underlying file system and the inherent dangers of pickle deserialization.",
"technicalDetails": "The root cause of this vulnerability is the combination of insecure deserialization practices and improper cache file management. In MONAI 1.6.0, the PersistentDataset class in monai/data/dataset.py explicitly prohibits the use of track_meta=True in conjunction with weights_only=True. This constraint forces the framework to utilize torch.load(weights_only=False) when loading cached MetaTensors.\nThe torch.load function, when invoked with weights_only=False, utilizes the Python pickle module to reconstruct objects. It is well-documented that pickle is inherently insecure as it can execute arbitrary code during the object reconstruction process if the input stream is manipulated.\nThe vulnerability is compounded by the implementation of cache helpers in monai/data/utils.py, which also utilize pickle.loads to process data retrieved from the cache. Furthermore, the cache key generation mechanism relies on hashlib.md5, which, while not a direct security flaw in this context, facilitates the deterministic creation of filenames that an attacker can predict and overwrite.\nThe attack flow proceeds as follows: 1) The attacker identifies a target application's cache directory (e.g., /tmp/monai_cache, ~/.cache/monai, or a shared scratch space). 2) The attacker crafts a malicious pickle payload designed to execute arbitrary shell commands or Python code. 3) The attacker writes this malicious payload to the cache directory, naming it to collide with an expected cache file key derived by the legitimate MONAI process. 4) A victim user executes a MONAI pipeline that points to the poisoned cache directory. 5) The PersistentDataset or cache utility reads the malicious file and passes it to the unsafe deserialization routine. 6) The pickle module reconstructs the malicious object, triggering the execution of the attacker's payload within the victim's process memory space.\nBecause the payload executes with the privileges of the victim user, the impact is comprehensive, including full access to the user's data, credentials, and network environment. This vulnerability is particularly dangerous in shared computing environments where multiple users share common storage locations, as it bypasses application-level security controls by targeting the underlying data ingestion pipeline."
}