High priorityDisclosed

Advisory · CVE-2026-100840

MONAI bundle config turns attacker packages into code execution

MONAI's bundle engine resolves _target_ values to arbitrary importables and passes $ expressions to eval(), so a malicious bundle runs code on load.

Vendor
Project-MONAI
Product
MONAI
Identifier / CWE
CVE-2026-100840
CWE-95
Action timing
Immediate
ELI5

Explain it like I’m five

MONAI opens shared recipe cards and follows whatever cooking instructions they contain, no questions asked. An attacker can print a recipe card that tells your kitchen to burn the house down.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Malicious bundle published

    An attacker publishes a bundle with crafted configuration containing arbitrary code.

  2. 02Victim loads the bundle

    The victim loads or runs the bundle with monai.bundle.load() or monai.bundle.run().

  3. 03_target_ resolves freely

    The bundle configuration engine resolves _target_ values to arbitrary importable callables with no allow list.

  4. 04eval executes expressions

    $ expressions are passed to Python eval(), executing the attacker's code.

What happened

MONAI through 1.6.0 (CVE-2026-100840, CVSS 8.5) contains a remote code execution vulnerability in its bundle configuration engine. The engine resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval().

Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().

What to do

  1. Upgrade MONAI past 1.6.0 once a fixed release is available and follow the project advisory.
  2. Only load bundles from trusted sources; treat third-party or downloaded bundles as untrusted input.
  3. Review where bundles are downloaded and loaded automatically in training and inference pipelines.
  4. Check for unexpected process or network activity from environments that loaded untrusted bundles.

Management note

MONAI bundles are effectively code, not data, in current versions. Model and bundle supply-chain discipline matters here: verify provenance before a shared bundle touches a training host.