CVE-2026-100845: MONAI before 1.6.0 Remote Code Execution via NumpyReader
MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allowpickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
MONAI deployments that load .npy or .npz files through the NumpyReader standard data pipeline are exposed if they use a version before 1.6.0. The practical risk is highest where those files can originate from untrusted or insufficiently validated sources.
What does an attacker need to exploit it?
An attacker needs to provide a crafted .npy file containing a malicious pickle payload and have it loaded by MONAI's NumpyReader. Exploitation requires user interaction, as reflected by the UI:R vector.
How can I tell whether my environment is affected?
Check whether the installed MONAI version is earlier than 1.6.0 and whether application workflows use NumpyReader to load .npy or .npz files. If both conditions are true, loading a malicious file can result in arbitrary code execution.