Sceawere
Vulnerability Detail
CVE-2026-100846UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MONAI Insecure Pickle Deserialization Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 1d ago
- Vendor
- Project-MONAI
- Product
- MONAI
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-09-27T02:17:23.283Z",
"pubdate": "2026-09-27T02:17:23.283Z",
"executiveSummary": "The MONAI framework, prior to version 1.5.2, contains a critical security vulnerability involving the deserialization of untrusted data within the 'algo_from_pickle' function located in 'monai/auto3dseg/utils.py'.\nThis vulnerability is classified as an Insecure Deserialization flaw, which allows for Remote Code Execution (RCE).\nThe root cause lies in the application's failure to perform input validation or sanitization before passing user-supplied '.pkl' files to the 'pickle.loads' function.\nBy crafting a malicious pickle stream containing an object with a custom '__reduce__' method, an attacker can trigger arbitrary code execution within the security context of the application process.\nThis vulnerability poses a severe risk to the confidentiality, integrity, and availability of the affected system, as successful exploitation grants an attacker the ability to execute arbitrary commands, potentially leading to full system compromise.\nThe requirement for exploitation is that an attacker must be able to influence the input provided to the 'algo_from_pickle' function, making applications that process externally sourced or uploaded model configuration files particularly susceptible.",
"technicalDetails": "The vulnerability resides in the 'algo_from_pickle' utility function defined in 'monai/auto3dseg/utils.py'.\nThe Python 'pickle' module is inherently insecure when used to deserialize data from untrusted sources. It provides a powerful mechanism for serializing and deserializing complex Python objects, but the deserialization process is not sandboxed. When 'pickle.loads' is invoked, it instantiates objects and can execute arbitrary functions defined within the byte stream.\nThe 'algo_from_pickle' function directly consumes a file path pointing to a '.pkl' file, opens the file, and passes the raw binary content directly into 'pickle.loads' without any cryptographic signing, integrity checking, or structural validation.\nAn attacker can exploit this by constructing a malicious Python object that implements the '__reduce__' special method. The 'pickle' module utilizes '__reduce__' during the reconstruction of objects; this method is intended to define how an object should be rebuilt, but it can be abused to return a callable (e.g., 'os.system') and a tuple of arguments to be executed upon deserialization.\nThe attack flow follows these steps: 1) The attacker creates a payload file containing a serialized object designed to execute malicious code (e.g., a reverse shell or file modification command). 2) The attacker ensures this file is accessible to the MONAI application, potentially through a file upload feature or by poisoning a shared storage location. 3) The attacker triggers the application logic that calls 'algo_from_pickle' with the path to the malicious file. 4) The application reads the malicious pickle stream. 5) During 'pickle.loads', the Python runtime executes the attacker-defined '__reduce__' method, resulting in the execution of the payload with the same privileges as the MONAI process.\nThis issue affects all versions of MONAI prior to 1.5.2. Because the 'pickle' module's functionality is fundamental to how this utility operates, the vulnerability is inherent to the logic of the function. No special authentication or complex network access is typically required beyond the ability to influence the file input mechanism used by the utility. Post-exploitation, an attacker gains the ability to execute system-level commands, leading to total takeover of the affected process context."
}