Skip to content
GHSA 89gg P5r5 Q6r4

GHSA 89gg P5r5 Q6r4

github.com • September 27, 2026

The algo_from_pickle function in monai/auto3dseg/utils.py causes pickle.loads(data_bytes) to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.

Generate the malicious file "attack_algo.pkl" through POC.

Ultimately, it will trigger pickle.load through a file to identify the command execution.

Causes of the vulnerability:

Arbitrary code execution

Repair suggestions Verify the data source and content before deserializing, or use a safe deserialization method

Extracted Entities