© 2025-2026 PySpect
First version without a known vulnerability: 1.6.0
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
Fixed in: 1.6.0
MONAI vulnerable to OS command injection
Fixed in: 1.6.0
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Fixed in: 1.6.0
MONAI: Unsafe functions lead to pickle deserialization rce
Fixed in: 1.6.0
MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
Fixed in: 1.5.2
Monai: Unsafe use of Pickle deserialization may lead to RCE
Fixed in: 1.5.1, 1.5.1rc1
MONAI: Unsafe torch usage may lead to arbitrary code execution
Fixed in: 1.5.1, 1.5.1rc1
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
Fixed in: 1.5.1, 1.5.1rc1