Vulnerability PYSEC-2026-4021
High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 days ago
September 27, 2026 at 02:17 AM UTC
No summary available
0.0.1 - 1.5.2rc1
0.0.1 - 1.5.2rc1
Details
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining reduce is executed during deserialization, resulting in arbitrary code execution in the context of the application.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
4 days ago
No summary available
0.0.1 - 1.5.2 PYSEC-2026-4020
0.0.1 - 1.5.2 PYSEC-2026-4020
Unknown
4 days ago
No summary available
0.0.1 - 1.6.0 PYSEC-2026-4015
0.0.1 - 1.6.0 PYSEC-2026-4015
Unknown
4 days ago
No summary available
PYSEC-2026-4016
High Risk
4 days ago
No summary available
0.0.1 - 1.6.0 PYSEC-2026-4017
0.0.1 - 1.6.0 PYSEC-2026-4017
Unknown
4 days ago
No summary available
0.0.1 - 1.5.2 PYSEC-2026-4018
0.0.1 - 1.5.2 PYSEC-2026-4018
Impacted packages
Timeline
Published
4 days ago
September 27, 2026 at 02:17 AM UTC
Fixed (1.5.2)
8 months ago
January 27, 2026 at 01:14 PM UTC
Last Modified
2 hours ago
October 01, 2026 at 09:15 AM UTC