Deserialization Flaw in MONAI AI Toolkit for Healthcare Imaging
CVE-2025-58757
8.8HIGH
What is CVE-2025-58757?
The MONAI toolkit, an AI resource used for healthcare imaging, contains a vulnerability in its pickle_operations function, located in monai/data/utils.py. This flaw arises from the automatic deserialization of dictionary key-value pairs that match a defined suffix without any security checks. As a result, this could potentially allow an attacker to execute arbitrary code. Currently, there are no known updated versions that resolve this issue.
Affected Version(s)
MONAI <= 1.5.0
