{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ml-ops/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:monai:monai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-100840"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MONAI (\u003c= 1.6.0)","MONAI (1.6.0)","MONAI (\u003c 1.6.0)","MONAI (\u003c 1.5.2)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","python","supply-chain","vulnerability","deserialization","rce","monai","code-execution","ml-ops","medical-imaging"],"_cs_type":"advisory","_cs_vendors":["MONAI"],"content_html":"\u003cp\u003eMONAI (Medical Open Network for AI) versions 1.6.0 and earlier contain a critical remote code execution (RCE) vulnerability within the bundle configuration engine. The vulnerability stems from the engine's failure to maintain an allow list when resolving '\u003cem\u003etarget\u003c/em\u003e' values to importable callables, combined with the unsafe passing of '$' expressions to the Python 'eval()' function.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by crafting a malicious bundle configuration file and distributing it to unsuspecting users. When a victim loads or executes this bundle using the affected 'monai.bundle.load()' or 'monai.bundle.run()' functions, the engine processes the malicious configuration, resulting in arbitrary code execution on the host system. This vulnerability poses a significant risk to researchers and developers who frequently download and integrate third-party AI bundles, as the malicious code triggers immediately upon processing the configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the Python interpreter running the MONAI environment. This could lead to full system compromise, exfiltration of sensitive medical imaging data, or lateral movement within research and development networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update MONAI to a version beyond 1.6.0.\u003c/li\u003e\n\u003cli\u003eAvoid loading MONAI bundles from untrusted sources or repositories.\u003c/li\u003e\n\u003cli\u003eInspect bundle configuration files ('bundle.json' or similar) for unexpected '\u003cem\u003etarget\u003c/em\u003e' definitions or embedded '$' expressions before execution.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for child processes spawned by Python interpreter instances running MONAI-related tasks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T03:05:08Z","date_published":"2026-09-27T03:04:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-monai-rce/","summary":"MONAI versions through 1.6.0 are vulnerable to remote code execution due to insecure deserialization and evaluation of arbitrary Python callables within bundle configuration files.","title":"Remote Code Execution in MONAI Bundle Configuration Engine","url":"https://feed.craftedsignal.io/briefs/2026-09-monai-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Ml-Ops","version":"https://jsonfeed.org/version/1.1"}