Skip to content
CVE Alert: CVE-2026-100846 – Project-MONAI

CVE Alert: CVE-2026-100846 – Project-MONAI

Redpacketsecurity •admin • September 27, 2026

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.

**Risk verdict:** High-impact code execution, but urgency cannot be fully ranked because exploitation, KEV, PoC and EPSS indicators were not provided.

**Why this matters:** Successful exploitation could let an attacker run code as the affected service, potentially exposing sensitive imaging data, credentials or models, or disrupting clinical and research workflows. The reported potential to affect systems beyond the vulnerable application increases concern where it has access to shared infrastructure.

**Most likely attack path:** An attacker would need network reachability and substantial privileges, then arrange for a crafted file to be processed; the attack also has high complexity and a stated attack requirement. The scoring data differs on whether user interaction is needed, so confirm the actual workflow. Changed scope indicates compromise could extend beyond the directly affected component.

**Who is most exposed:** Prioritise research, healthcare and AI teams running self-hosted imaging or model-training pipelines, especially services that ingest externally supplied files or operate with broad system permissions.

Alert on unexpected child processes spawned by Python-based pipeline workers.

Review logs for unusual file uploads, imports or processing jobs by privileged accounts.

Hunt for unexpected outbound connections, new files or changes to model and pipeline assets.

Mitigation and prioritisation:

Upgrade to the vendor-fixed release; inventory embedded and transitive deployments.

Until upgraded, prevent untrusted files reaching the vulnerable deserialisation workflow.

Run workers with least privilege, isolated storage and restricted egress.

Test pipeline compatibility, then expedite change approval; check for signs of prior compromise before redeployment.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities