Deserialization Flaw in MONAI AI Toolkit for Healthcare Imaging
CVE-2025-58757

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
8 September 2025

What is CVE-2025-58757?

The MONAI toolkit, an AI resource used for healthcare imaging, contains a vulnerability in its pickle_operations function, located in monai/data/utils.py. This flaw arises from the automatic deserialization of dictionary key-value pairs that match a defined suffix without any security checks. As a result, this could potentially allow an attacker to execute arbitrary code. Currently, there are no known updated versions that resolve this issue.

Affected Version(s)

MONAI <= 1.5.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.