Sceawere
Vulnerability Detail
CVE-2026-100845UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MONAI Unsafe Deserialization Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Project-MONAI
- Product
- MONAI
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-27T02:17:23.140Z",
"pubdate": "2026-09-27T02:17:23.140Z",
"executiveSummary": "MONAI versions prior to 1.6.0 contain a critical unsafe deserialization vulnerability within the NumpyReader class.\nThe flaw originates from the unconditional invocation of numpy.load with the allow_pickle=True parameter enabled, which processes .npy and .npz file formats.\nBy crafting a malicious archive containing embedded pickle payloads, an unauthenticated attacker can achieve arbitrary code execution on the host system.\nThis vulnerability poses a significant risk to data pipelines, as the execution of malicious instructions occurs automatically when the MONAI framework attempts to ingest or process tainted data files.\nThe impact is severe, potentially leading to full system compromise, data exfiltration, or unauthorized lateral movement within the environment where MONAI is deployed.\nExploitation does not require prior authentication, as the attack vector is inherent to the data ingestion pipeline. Organizations relying on MONAI for medical imaging or research data processing are advised to treat this as a high-priority security concern.",
"technicalDetails": "The vulnerability resides in the MONAI library's NumpyReader component, specifically in how it handles file-based data ingestion. The root cause is the insecure use of the numpy.load function, which is designed to deserialize NumPy-specific data formats.\nIn the affected versions, MONAI developers implemented a configuration that forces allow_pickle=True when interacting with .npy or .npz files. The pickle module in Python is inherently insecure, as it is capable of executing arbitrary code during the unpickling process if the input stream is manipulated by a malicious actor.\nThe attack flow begins when an attacker provides a crafted .npy or .npz file to a system utilizing MONAI's data pipeline. Because the NumpyReader is used as a standard component for loading these file types, the application automatically invokes numpy.load on the untrusted file.\nUpon processing, the numpy.load function interprets the contents of the malicious file. The embedded pickle payload is deserialized by the Python interpreter, triggering the execution of pre-defined malicious commands within the context of the running application process.\nSince MONAI is frequently integrated into medical imaging pipelines, the application process often runs with elevated permissions or within sensitive environments. This allows an attacker to gain execution privileges equivalent to the service account running the MONAI process. There are no authentication mechanisms or authorization checks to prevent this, as the ingestion of data files is typically treated as a standard functional requirement.\nThe vulnerability effectively bypasses traditional input validation, as the malicious code is hidden within the structure of a serialized data object. Post-exploitation, an attacker can perform various actions, such as establishing a reverse shell, reading local files, or escalating privileges on the underlying operating system. The lack of validation on the integrity of the data source ensures that any system relying on automated data ingestion pipelines is susceptible to this remote code execution vector."
}