Sceawere
Vulnerability Detail
CVE-2026-100842UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MONAI Eval Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 1d ago
- Vendor
- Project-MONAI
- Product
- MONAI
- Attack Type
- Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.Name nodes and therefore bypass the allowlist. Because the shape value originates from bundle metadata consumed by _get_real_input_data and verify_net_in_out (reachable through the bundle 'verify_net_in_out' CLI flow), an attacker who can influence a bundle's metadata can escape the eval sandbox via object introspection chains and achieve code execution in this non-default flow.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-09-27T02:17:22.693Z",
"pubdate": "2026-09-27T02:17:22.693Z",
"executiveSummary": "MONAI versions through 1.6.0 are vulnerable to an eval injection flaw located in the monai/bundle/scripts.py file.\nThe vulnerability resides within the _get_fake_spatial_shape() function, which fails to adequately sanitize input expressions before passing them to the Python eval() function.\nBy bypassing a flawed AST-based allowlist, an attacker can execute arbitrary Python code via crafted bundle metadata.\nThe attack is reachable through the bundle 'verify_net_in_out' CLI flow, which processes untrusted metadata.\nSuccessful exploitation allows for complete remote code execution (RCE) on the host system running the MONAI bundle verification.\nThe risk is critical for users or automated systems that process untrusted or externally sourced MONAI bundles, as the vulnerability does not rely on traditional object naming but rather on deep object introspection chains that evade the existing security checks.",
"technicalDetails": "The vulnerability exists in the _get_fake_spatial_shape() function within monai/bundle/scripts.py. This function is intended to validate shape expressions provided in MONAI bundle metadata by analyzing the abstract syntax tree (AST) of the input string. The implemented security control explicitly iterates through the AST and restricts valid nodes to ast.Name, specifically enforcing that these names must be either 'p' or 'n'.\nThe security mechanism fails because it treats the absence of restricted ast.Name nodes as a success condition. Python expressions can be constructed using alternative AST node types such as ast.Constant, ast.Attribute, ast.Subscript, and ast.Call, which contain no ast.Name nodes. Consequently, these malicious constructs completely bypass the allowlist check.\nAn attacker can leverage this oversight to bypass the sandbox by utilizing object introspection chains. By crafting a payload such as '(1).__class__.__bases__[0].__subclasses__()' or 'int.__class__.__init__.__globals__', an attacker can navigate the Python object hierarchy to access sensitive modules, such as os or subprocess, which are typically restricted or unavailable in secure environments.\nThe attack flow originates from bundle metadata processed by _get_real_input_data and verify_net_in_out. When a user or an automated CI/CD pipeline triggers the 'verify_net_in_out' CLI flow on a maliciously crafted bundle, the unsanitized metadata string is parsed and eventually evaluated by the vulnerable function. Because the evaluation happens within the context of the MONAI execution environment, the attacker gains the same privileges as the user or service account executing the verification command.\nThis vulnerability is particularly dangerous because it does not require authentication to the running system; it is triggered by the ingestion of a malicious input file (bundle metadata). The impact is total system compromise, as the ability to execute arbitrary Python code permits the attacker to read, modify, or delete files, establish persistence, or initiate lateral movement within the network depending on the environment's security posture and existing permissions.\nThe flaw affects all versions of MONAI through 1.6.0. No special privileges are required by the attacker other than the ability to influence or supply the metadata that the bundle verification process consumes."
}