CyberRota Analysis
AI-GeneratedThe vulnerability in MONAI allows remote code execution due to improper handling of bundle configuration, enabling attackers to craft malicious bundles that execute arbitrary code when loaded by victims. This poses a significant risk to any users of MONAI versions up to 1.6.0, particularly in environments where untrusted bundles may be loaded. Organizations utilizing MONAI for medical imaging or related applications should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().
Related CVEs
Other vulnerabilities affecting the same vendor(s)