Why a MONAI Model Bundle Deserves a Software Review
A machine-learning model arrives as files, configuration and cached data. The MONAI advisory set shows several ways those inputs can become Python code when a pipeline loads them. Six previously disclosed issues now collected under public CVE records turn that familiar AI supply chain into a clear execution boundary.
The earliest primary advisory dates to April, with others published in June and August 2026. NVD published the corresponding records on 27 September. This is delayed indexing of missed material, not a new breach, a new disclosure or evidence that attackers are exploiting MONAI today.
A bundle configuration can name code to import
CVE-2026-100840 affects MONAI through 1.6.0. The primary advisory says the bundle engine accepts arbitrary importable callables in _target_ values and evaluates expressions prefixed with $. Loading or running a malicious bundle can therefore execute code with the user’s privileges. The advisory lists no patched version.
This matters because model hubs and research repositories encourage users to treat a bundle as portable content. The technical behaviour is closer to installing and running software. A signature or review policy needs to cover configuration and helper code, not only model weights.
The cache can execute another user’s pickle
CVE-2026-100841 affects all released versions at the time of its advisory, with no patched version listed. A local user who can write into a shared or world-writable cache directory can place a malicious pickle that another MONAI pipeline later deserialises.
Shared high-performance computing storage makes this more than a single-user desktop concern. A cache intended to save training time can become a cross-user execution channel if ownership, permissions and cache keys are treated as performance details rather than security controls.
Four more file and command paths need review
- CVE-2026-100843 covers unsafe
pickle.loads()inalgo_from_pickle()before 1.6.0, documented in the vendor advisory. - CVE-2026-100846 describes the same named function before 1.5.2 in a separate vendor advisory. The overlap and different fixed-version claims should be treated as a coordination ambiguity, not silently merged.
- CVE-2026-100844 covers shell command injection before 1.6.0 when crafted nnUNet configuration or arguments reach
subprocesswithshell=True. - CVE-2026-100845 covers NumPy loading with
allow_pickle=Truebefore 1.6.0, allowing a crafted.npyor.npzfile to carry executable pickle content.
The separate identifiers matter operationally because they describe different trust decisions: a bundle configuration, a shared cache, an explicit pickle import, a training command and an image-data loader. Scanning for one function or upgrading one workflow is not a complete exposure check.
What medical-AI teams should do
- Upgrade where fixes exist. Move to at least MONAI 1.6.0 for the older pickle, command and NumPy paths. That does not close the bundle or shared-cache advisories, both of which list no patched version.
- Treat bundles as code. Accept them only from reviewed sources, pin exact versions and verify signatures or hashes before use.
- Do not share writable caches across trust boundaries. Use per-user directories with restrictive permissions and rebuild caches from trusted inputs.
- Disable unsafe formats. Prefer formats and loaders that do not require Python pickle or dynamic evaluation.
- Contain training and inference. Run third-party models and data in isolated, least-privileged environments without production credentials or unrestricted network egress.
- Review provenance at every layer. Model weights, Python packages, configuration, preprocessing code and data files can each provide an execution path.
BlackTree has previously covered how AI systems can cross a boundary through material that looks like ordinary input. MONAI shows the same problem in a healthcare engineering context: Python’s flexible data formats make collaboration easy, but they also make the difference between content and code depend on the loader.
The reviewed material does not establish clinical-system compromise, patient-data access or malicious exploitation. The strategic risk is the normalisation of executable artefacts inside research and care pipelines where model files may receive less scrutiny than conventional software.
Sources
- MONAI bundle advisory, published 21 August 2026 at 14:15:00 UTC, 16:15:00 CEST.
- MONAI shared-cache advisory, published 21 August 2026 at 14:13:43 UTC, 16:13:43 CEST.
- MONAI pickle advisory, command-injection advisory and NumPy advisory, published 11 June 2026 between 12:40 and 12:42 UTC, 14:40 and 14:42 CEST.
- Earlier algo_from_pickle advisory, published 3 April 2026 at 22:50:09 UTC, 00:50:09 CEST on 4 April.
- NVD published the six records on 27 September 2026 between 02:17:22 and 02:17:23 UTC, 04:17:22 and 04:17:23 CEST. The reviewed NVD entries supplied the new indexing signal.


