© 2025-2026 PySpect
First version without a known vulnerability: 1.6.1rc0
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.Name nodes and therefore bypass the allowlist. Because the shape value originates from bundle metadata consumed by _get_real_input_data and verify_net_in_out (reachable through the bundle 'verify_net_in_out' CLI flow), an attacker who can influence a bundle's metadata can escape the eval sandbox via object introspection chains and achieve code execution in this non-default flow.
Fixed in: 1.6.1rc0
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().
Fixed in: 1.6.1rc0
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
Fixed in: 1.6.0
MONAI vulnerable to OS command injection
Fixed in: 1.6.0
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Fixed in: 1.6.0
MONAI: Unsafe functions lead to pickle deserialization rce
Fixed in: 1.6.0, 1.5.2
MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
Fixed in: 1.5.2
Monai: Unsafe use of Pickle deserialization may lead to RCE
Fixed in: 1.5.1, 1.5.1rc1
MONAI: Unsafe torch usage may lead to arbitrary code execution
Fixed in: 1.5.1, 1.5.1rc1
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
Fixed in: 1.5.1, 1.5.1rc1