Back Redpacketsecurity CVE Alert: CVE-2026-100840 – Project-MONAI
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().
**Risk verdict:** High impact, but the supplied data does not include KEV, SSVC, PoC or EPSS status, so active exploitation and immediate priority cannot be confirmed.
**Why this matters:** Successful exploitation could compromise the confidentiality, integrity and availability of the system processing a crafted configuration. A realistic goal is to run code in a user’s environment, potentially exposing research data, credentials or other accessible assets.
**Most likely attack path:** An attacker provides a malicious bundle and persuades a user or automated workflow to load or run it. The attack requires local execution and user interaction, but no prior privileges or complex conditions; the stated scope is unchanged, so direct impact is on the affected system rather than a separately scoped component.
**Who is most exposed:** Prioritise teams using MONAI in medical-imaging, AI research and model-development workflows, especially where bundles are imported from external repositories or shared with collaborators.
Review process and shell logs for unexpected child processes launched by MONAI workloads.
Alert on outbound connections or file writes immediately after bundle loading.
Audit bundle provenance and identify workflows loading untrusted configurations.
Examine affected hosts for unexpected changes to scripts, models or credentials.
Mitigation and prioritisation
Confirm KEV, SSVC, PoC and EPSS status; if KEV is true or EPSS is at least 0.5, treat as priority 1.
Upgrade to a vendor-fixed release; confirm the fixed release with the advisory before deployment.
Until patched, block untrusted bundles and restrict loading to vetted, integrity-checked sources.
Test changes in representative workflows, then roll out promptly; isolate hosts that loaded suspicious bundles.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
