Advisory · CVE-2026-100840
MONAI bundle config turns attacker packages into code execution
MONAI's bundle engine resolves _target_ values to arbitrary importables and passes $ expressions to eval(), so a malicious bundle runs code on load.
- Vendor
- Project-MONAI
- Product
- MONAI
- Identifier / CWE
- CVE-2026-100840
CWE-95 - Action timing
- Immediate
Explain it like I’m five
MONAI opens shared recipe cards and follows whatever cooking instructions they contain, no questions asked. An attacker can print a recipe card that tells your kitchen to burn the house down.
- 01Malicious bundle published
An attacker publishes a bundle with crafted configuration containing arbitrary code.
- 02Victim loads the bundle
The victim loads or runs the bundle with monai.bundle.load() or monai.bundle.run().
- 03_target_ resolves freely
The bundle configuration engine resolves _target_ values to arbitrary importable callables with no allow list.
- 04eval executes expressions
$ expressions are passed to Python eval(), executing the attacker's code.
What happened
MONAI through 1.6.0 (CVE-2026-100840, CVSS 8.5) contains a remote code execution vulnerability in its bundle configuration engine. The engine resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval().
Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().
What to do
- Upgrade MONAI past 1.6.0 once a fixed release is available and follow the project advisory.
- Only load bundles from trusted sources; treat third-party or downloaded bundles as untrusted input.
- Review where bundles are downloaded and loaded automatically in training and inference pipelines.
- Check for unexpected process or network activity from environments that loaded untrusted bundles.
Management note
MONAI bundles are effectively code, not data, in current versions. Model and bundle supply-chain discipline matters here: verify provenance before a shared bundle touches a training host.