Deserialization Flaw in MONAI AI Toolkit for Medical Imaging
CVE-2025-58756
8.8HIGH
What is CVE-2025-58756?
The MONAI AI toolkit for healthcare imaging contains a significant deserialization vulnerability due to insecure loading practices involving checkpoint files. In versions up to 1.5.0, while secure loading is supported in some functions, other areas of the codebase fail to ensure security. This creates a risk for users who load potentially malicious pre-trained models or checkpoints from external sources, as it allows for unauthorized code execution. As of this publication, there are no known fixes available for this vulnerability, leaving users exposed.
Affected Version(s)
MONAI <= 1.5.0
