CVE-2026-100841: MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination trackmeta=True with weightsonly=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weightsonly=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cachedir (e.g. /tmp/monaicache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict write access to MONAI cache directories such as /tmp/monai_cache, HPC scratch, and ~/.cache/monai; do not use shared or world-writable cache_dir locations for PersistentDataset.
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Users whose MONAI workloads read from a cache_dir that another local user can write to are exposed. Examples given include shared or world-writable cache directories such as /tmp/monai_cache, HPC scratch space, and ~/.cache/monai.
What does an attacker need to exploit it?
An attacker needs local write access to the cache directory used by the target MONAI pipeline. They can place a malicious pickle cache file that is deserialized when the target later reads the cache.
Are default MONAI tensor settings relevant?
Yes. MetaTensors are the default tensor type in MONAI versions 1.0 and later, and caching them can force torch.load to use weights_only=False because the track_meta=True and weights_only=True combination is rejected.
What can be done if no patch is available?
Ensure cache_dir locations are not shared or writable by untrusted local users. Use a cache directory with permissions that prevent other users from creating or modifying cache files, and avoid world-writable or shared scratch cache locations.
How can I determine whether a deployment is affected?
Check whether the deployment uses the monai pip package and whether its PersistentDataset or related cache handling reads cache content from a directory writable by another user. All released versions of the monai pip package are reported affected, with no patched version available as of the advisory.