CVE-2025-58755

Source
https://cve.org/CVERecord?id=CVE-2025-58755
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58755.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-58755
Aliases
Published
2025-09-08T23:35:41.506Z
Modified
2026-05-20T08:11:37.892991191Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
MONAI has path traversal issue that may lead to arbitrary file writes
Details

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function zip_file.extractall(output_dir) is used directly to process compressed files. It is used in many places in the project. In versions up to and including 1.5.0, when the Zip file containing malicious content is decompressed, it overwrites the system files. In addition, the project allows the download of the zip content through the link, which increases the scope of exploitation of this vulnerability. As of time of publication, no known fixed versions are available.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58755.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/project-monai/monai

Affected ranges

Type
GIT
Repo
https://github.com/project-monai/monai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.5.0"
        }
    ]
}

Affected versions

0.*
0.1.0
0.1.0rc1
0.1.0rc2
0.1a1.dev7
0.1a1.dev8
0.1a1.dev9
0.2.0
0.2.0rc1
0.2.0rc2
0.2.0rc3
0.3.0
0.3.0rc1
0.3.0rc2
0.3.0rc3
0.3.0rc4
0.4.0
0.4.0rc1
0.4.0rc2
0.5.0
0.5.0rc1
0.5.0rc2
0.5.0rc3
0.5.0rc4
0.5.0rc5
0.5.1
0.5.2
0.6.0
0.6.0rc1
0.6.0rc2
0.7.0
0.7.0rc1
0.7.0rc2
0.7.0rc3
0.7.0rc4
0.7.0rc5
0.8.0
0.8.0rc1
0.8.0rc2
0.8.0rc3
0.8.1
0.8.1rc1
0.8.1rc2
0.8.1rc3
0.8.1rc4
0.8.1rc5
0.9.0
0.9.0rc1
0.9.0rc2
0.9.0rc3
0.9.1
0.9.1rc1
0.9.1rc2
0.9.1rc3
0.9.1rc4
0.9.1rc5
1.*
1.0.0rc1
1.0.0rc2
1.0.0rc3
1.1.0
1.1.0rc1
1.1.0rc2
1.2.0
1.2.0rc1
1.2.0rc2
1.2.0rc4
1.2.0rc5
1.2.0rc6
1.2.0rc7
1.3.0
1.3.0rc1
1.3.0rc2
1.3.0rc3
1.3.0rc4
1.3.0rc5
1.3.1
1.3.1rc1
1.3.1rc2
1.3.1rc3
1.3.1rc4
1.3.1rc5
1.3.1rc6
1.3.1rc7
1.3.1rc8
1.3.3rc1
1.4.0
1.4.0rc1
1.4.0rc10
1.4.0rc11
1.4.0rc12
1.4.0rc2
1.4.0rc3
1.4.0rc4
1.4.0rc5
1.4.0rc6
1.4.0rc7
1.4.0rc8
1.4.0rc9
1.4.1rc1
1.5.0
1.5.0rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58755.json"