BlackTree Security · Infrastructure · Automation · AI

Why a MONAI Model Bundle Deserves a Software Review

A machine-learning model arrives as files, configuration and cached data. The MONAI advisory set shows several ways those inputs can become Python code when a pipeline loads them. Six previously disclosed issues now collected under public CVE records turn that familiar AI supply chain into a clear execution boundary.

The earliest primary advisory dates to April, with others published in June and August 2026. NVD published the corresponding records on 27 September. This is delayed indexing of missed material, not a new breach, a new disclosure or evidence that attackers are exploiting MONAI today.

A bundle configuration can name code to import

CVE-2026-100840 affects MONAI through 1.6.0. The primary advisory says the bundle engine accepts arbitrary importable callables in _target_ values and evaluates expressions prefixed with $. Loading or running a malicious bundle can therefore execute code with the user’s privileges. The advisory lists no patched version.

This matters because model hubs and research repositories encourage users to treat a bundle as portable content. The technical behaviour is closer to installing and running software. A signature or review policy needs to cover configuration and helper code, not only model weights.

The cache can execute another user’s pickle

CVE-2026-100841 affects all released versions at the time of its advisory, with no patched version listed. A local user who can write into a shared or world-writable cache directory can place a malicious pickle that another MONAI pipeline later deserialises.

Shared high-performance computing storage makes this more than a single-user desktop concern. A cache intended to save training time can become a cross-user execution channel if ownership, permissions and cache keys are treated as performance details rather than security controls.

Four more file and command paths need review

The separate identifiers matter operationally because they describe different trust decisions: a bundle configuration, a shared cache, an explicit pickle import, a training command and an image-data loader. Scanning for one function or upgrading one workflow is not a complete exposure check.

What medical-AI teams should do

  • Upgrade where fixes exist. Move to at least MONAI 1.6.0 for the older pickle, command and NumPy paths. That does not close the bundle or shared-cache advisories, both of which list no patched version.
  • Treat bundles as code. Accept them only from reviewed sources, pin exact versions and verify signatures or hashes before use.
  • Do not share writable caches across trust boundaries. Use per-user directories with restrictive permissions and rebuild caches from trusted inputs.
  • Disable unsafe formats. Prefer formats and loaders that do not require Python pickle or dynamic evaluation.
  • Contain training and inference. Run third-party models and data in isolated, least-privileged environments without production credentials or unrestricted network egress.
  • Review provenance at every layer. Model weights, Python packages, configuration, preprocessing code and data files can each provide an execution path.

BlackTree has previously covered how AI systems can cross a boundary through material that looks like ordinary input. MONAI shows the same problem in a healthcare engineering context: Python’s flexible data formats make collaboration easy, but they also make the difference between content and code depend on the loader.

The reviewed material does not establish clinical-system compromise, patient-data access or malicious exploitation. The strategic risk is the normalisation of executable artefacts inside research and care pipelines where model files may receive less scrutiny than conventional software.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *