Vulnerabilidad · Publicado 27/09/2026
MONAI versions anteriores a la 1.5.2 contiene una vulnerabilidad de deserialización de datos no confiables en la función algo_from_pickle que procesa archivos .pkl sin validación. Un atacante puede ejecutar código arbitrario mediante un archivo pickle manipulado si la aplicación lo procesa. Esta vulnerabilidad afecta directamente plataformas de análisis de imágenes médicas 3D en instituciones sanitarias y centros de investigación de LATAM.
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.
Score: 7.6/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-502
Publicado en NIST NVD.