Sceawere

Vulnerability Detail

CVE-2026-100845UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MONAI Unsafe Deserialization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Project-MONAI
Product
MONAI
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-09-27T02:17:23.140Z",
  "pubdate": "2026-09-27T02:17:23.140Z",
  "executiveSummary": "MONAI versions prior to 1.6.0 contain a critical unsafe deserialization vulnerability within the NumpyReader class.\nThe flaw originates from the unconditional invocation of numpy.load with the allow_pickle=True parameter enabled, which processes .npy and .npz file formats.\nBy crafting a malicious archive containing embedded pickle payloads, an unauthenticated attacker can achieve arbitrary code execution on the host system.\nThis vulnerability poses a significant risk to data pipelines, as the execution of malicious instructions occurs automatically when the MONAI framework attempts to ingest or process tainted data files.\nThe impact is severe, potentially leading to full system compromise, data exfiltration, or unauthorized lateral movement within the environment where MONAI is deployed.\nExploitation does not require prior authentication, as the attack vector is inherent to the data ingestion pipeline. Organizations relying on MONAI for medical imaging or research data processing are advised to treat this as a high-priority security concern.",
  "technicalDetails": "The vulnerability resides in the MONAI library's NumpyReader component, specifically in how it handles file-based data ingestion. The root cause is the insecure use of the numpy.load function, which is designed to deserialize NumPy-specific data formats.\nIn the affected versions, MONAI developers implemented a configuration that forces allow_pickle=True when interacting with .npy or .npz files. The pickle module in Python is inherently insecure, as it is capable of executing arbitrary code during the unpickling process if the input stream is manipulated by a malicious actor.\nThe attack flow begins when an attacker provides a crafted .npy or .npz file to a system utilizing MONAI's data pipeline. Because the NumpyReader is used as a standard component for loading these file types, the application automatically invokes numpy.load on the untrusted file.\nUpon processing, the numpy.load function interprets the contents of the malicious file. The embedded pickle payload is deserialized by the Python interpreter, triggering the execution of pre-defined malicious commands within the context of the running application process.\nSince MONAI is frequently integrated into medical imaging pipelines, the application process often runs with elevated permissions or within sensitive environments. This allows an attacker to gain execution privileges equivalent to the service account running the MONAI process. There are no authentication mechanisms or authorization checks to prevent this, as the ingestion of data files is typically treated as a standard functional requirement.\nThe vulnerability effectively bypasses traditional input validation, as the malicious code is hidden within the structure of a serialized data object. Post-exploitation, an attacker can perform various actions, such as establishing a reverse shell, reading local files, or escalating privileges on the underlying operating system. The lack of validation on the integrity of the data source ensures that any system relying on automated data ingestion pipelines is susceptible to this remote code execution vector."
}
CVE-2026-100845: MONAI Unsafe Deserialization Vulnerability (HIGH Severity, CVSS: 7.8) | Sceawere