Tag
high
advisory
Remote Code Execution in MONAI Bundle Configuration Engine
2 TTPs 1 CVEMONAI versions through 1.6.0 are vulnerable to remote code execution due to insecure deserialization and evaluation of arbitrary Python callables within bundle configuration files.
MONAI +3
remote-code-execution
python
supply-chain
vulnerability
deserialization
rce
code-execution
ml-ops
+1
2t
1c
high
advisory
OS Command Injection Vulnerability in MONAI
1 rule 2 TTPsThe MONAI library contains a command injection vulnerability where unsanitized configuration values in YAML files are passed to shell execution, allowing arbitrary code execution.
MONAI
rce
command-injection
python
1r
2t
high
advisory
MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization
2 rules 1 TTPThe MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.
MONAI
pickle
rce
insecure-deserialization
python
2r
1t