rootpwn

high · CVSS v3 7.8 · CVSS v4 8.5 · EPSS 0.00188

CVE-2026-100843

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa…

Description

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

Scores

Severity
high
CVSS v2
7.2
CVSS v3
7.8
CVSS v4
8.5
EPSS
0.00188

← All CVEs