Project-MONAI MONAI
7 known vulnerabilities in Project-MONAI MONAI, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100846 CVSS 8.8 high MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in…
- CVE-2026-100845 CVSS 8.5 high MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with…
- CVE-2026-100844 CVSS 8.6 high MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner)…
- CVE-2026-100843 CVSS 8.5 high MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads()…
- CVE-2026-100842 CVSS 7.3 high MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function…
- CVE-2026-100841 CVSS 8.5 high In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True…
- CVE-2026-100840 CVSS 8.5 high MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to…