Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100842— MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains

Quick assessment

Affected
Project-MONAI MONAI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MONAI 1.6.0 及之前版本在 文件的 函数中存在一个 eval 注入漏洞。该函数使用一个辅助工具验证形状表达式,该工具通过遍历抽象语法树(AST)并仅收集 节点来实现,拒绝除 和 以外的任何名称,然后才将字符串传递给 。如果表达式完全由常量以及属性、下标或调用节点构成(例如 或 ),则不包含任何 节点,从而可以绕过白名单检查。由于形状值来源于 bundle 元数据,并且该元数据会被 和 函数消费(可通过 bundle 的 CLI 流程访问),因此能够影响 bundle 元数据的攻击者可以利用对象内省链逃离

CVSS 7.0 · High EPSS 0.15% · P3

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100842

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains
Source: CVE Program / CVE List V5
Vulnerability Description
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.Name nodes and therefore bypass the allowlist. Because the shape value originates from bundle metadata consumed by _get_real_input_data and verify_net_in_out (reachable through the bundle 'verify_net_in_out' CLI flow), an attacker who can influence a bundle's metadata can escape the eval sandbox via object introspection chains and achieve code execution in this non-default flow.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Project-MONAI MONAI 0 ~ 1.6.0 -

II. Public POCs for CVE-2026-100842

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100842

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100842 (1)

Other References for CVE-2026-100842 (1)

Same Patch Batch · Project-MONAI · 2026-09-27 · 7 CVEs total

CVE-2026-100844 8.4 HIGH MONAI before 1.6.0 OS Command Injection via dataset_name_or_id
CVE-2026-100841 7.8 HIGH MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache
CVE-2026-100843 7.8 HIGH MONAI before 1.6.0 Remote Code Execution via algo_from_pickle
CVE-2026-100845 7.8 HIGH MONAI before 1.6.0 Remote Code Execution via NumpyReader
CVE-2026-100840 7.8 HIGH MONAI through 1.6.0 Remote Code Execution via bundle configuration
CVE-2026-100846 7.6 HIGH MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization

IV. Related Vulnerabilities

V. Comments for CVE-2026-100842

No comments yet


Leave a comment