MONAI 1.6.0 及之前版本在 bundle 配置引擎中存在远程代码执行漏洞。该漏洞允许 _target_ 值被解析为任意可导入的可调用对象,而未设置允许列表(allow list);同时,$ 表达式会被直接传递给 Python 的 eval() 函数执行。攻击者可以发布包含精心构造配置的恶意 bundle,当受害者使用 monai.bundle.load() 或 monai.bundle.run() 加载该 bundle 时,其中的任意代码将被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Project-MONAI | MONAI | 0 ~ 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100844 | 8.4 HIGH | MONAI before 1.6.0 OS Command Injection via dataset_name_or_id |
| CVE-2026-100841 | 7.8 HIGH | MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache |
| CVE-2026-100843 | 7.8 HIGH | MONAI before 1.6.0 Remote Code Execution via algo_from_pickle |
| CVE-2026-100845 | 7.8 HIGH | MONAI before 1.6.0 Remote Code Execution via NumpyReader |
| CVE-2026-100846 | 7.6 HIGH | MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization |
| CVE-2026-100842 | 7.0 HIGH | MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains |
No comments yet