在 MONAI 1.6.0 版本之前,NumpyReader 类中存在不安全的反序列化漏洞。该漏洞在加载 .npy 和 .npz 文件时,无条件地使用 numpy.load 并设置 allow_pickle=True。攻击者可以构造带有恶意 pickle 负载的 .npy 文件,当这些文件通过 MONAI 的标准数据管道加载时,将执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Project-MONAI | MONAI | 0 ~ 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100844 | 8.4 HIGH | MONAI before 1.6.0 OS Command Injection via dataset_name_or_id |
| CVE-2026-100841 | 7.8 HIGH | MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache |
| CVE-2026-100843 | 7.8 HIGH | MONAI before 1.6.0 Remote Code Execution via algo_from_pickle |
| CVE-2026-100840 | 7.8 HIGH | MONAI through 1.6.0 Remote Code Execution via bundle configuration |
| CVE-2026-100846 | 7.6 HIGH | MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization |
| CVE-2026-100842 | 7.0 HIGH | MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains |
No comments yet