The algo_from_pickle function in monai/auto3dseg/utils.py causes pickle.loads(data_bytes) to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.
Generate the malicious file "attack_algo.pkl" through POC.
Ultimately, it will trigger pickle.load through a file to identify the command execution.
Causes of the vulnerability:
Arbitrary code execution
Repair suggestions Verify the data source and content before deserializing, or use a safe deserialization method
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
